@@ -638,7 +638,9 @@ This table maps the user types to the corresponding use cases and the security l
> Describe what risks are delegated to other components, as well as what security functionalities this product offers to things integrated with it.
## 4.11 Support period
VPN software is often installed on devices best defined as routers or firewalls.
## 4.X Support period
Enterprise VPN software is a challenging and resource-heavy deployment process, and with regular security updates should be expected to be operational for 10 or more years.
@@ -681,13 +683,15 @@ Enterprise VPN software is a challenging and resource-heavy deployment process,
- Activity logs
- Configuration data
- Management application certificates
- CA information, certificates & keys (public, private, PSK)
- End-point details including authentication, location, and potential PII
### C.1.2 Product functions
> See the functions in Section 4.4.
A basic overview of VPN functions follows. See clause 4.TK for a detailed overview of the essential functions of a VPN product.
TODO delete and reference clause 4 or reword
TODO: should this switch places with the content in the Essential Functions section?
* Edge - uses a public network to communicate with the restricted use network
* Gateway - provides link between public network and restricted
@@ -705,18 +709,20 @@ TODO delete and reference clause 4 or reword
> Example threats can be found in the same documents suggested in the section on security requirements.
- Untrusted traffic gaining access using illicitly acquired configuration data
- Endpoint malware hijacking traffic or recording activity
- End-point malware hijacking traffic or recording activity
- Social engineering resulting in credential harvesting
-
- Unauthorised but authenticated access by a compromised node/end-point
- Misconfigured end-point exposing authentication information
- DoS attack, particularly if a node/end-point is outside of a firewall
- Activity exposure via unauthorised log access
- Out-of-the-box configuration that necessarily requires modification to be secure
## C.3 Assumptions
> List assumptions that are relevant to the risk analysis for these threats. Everything is hackable if you try hard enough. What kinds of threats are in and out of scope? What are you assuming is the sophistication of attack? Relate to use cases.
- Not being attacked by a state actor
- Not using sophisticated or expensive hardware snooping techniques
- No secret hardware backdoors
[//]:#(- No secret hardware backdoors)
[//]:#(Do hardware backdoors need to be addressed in due diligence for remote data processing on manufacturer hardware? or is that more information than strictly necessary?)