Verified Commit 0f88da08 authored by Aki Braun's avatar Aki Braun
Browse files

Clause 4 RDPS edits

parent 1df861ab
Loading
Loading
Loading
Loading
+9 −30
Original line number Diff line number Diff line
@@ -251,10 +251,6 @@ For the purposes of the present document, the following abbreviations apply:

<mark>Editor’s Note: RDPS are explicitly identified in the product context. RDPS interfaces and trust boundaries are described in the product architecture overview. RDPS assumptions and constraints are reflected in the operational environment description. Where relevant, dependencies on third party cloud solutions are included in the distribution of security functions.</mark>

## 4.0 Introduction

Editor's note: this Introduction Clause is optional, used for any introductory text/sentence to avoid hanging paragraphs.

## 4.1 Product Functions

<mark>Editor’s Note: Product functions should be clearly defined and granular enough to inform decision-making regarding capability-based applicability of related security controls. The recommended structure for doing this is a hierarchical functional decomposition, wherein each larger functional capability is broken down into its constituent parts. This enables manufacturers to easily derive whether their product supports parts of or all of a specific function.</mark>
@@ -303,18 +299,8 @@ During reasonably foreseeable use, VPN nodes may:

## 4.2 Product Architecture

(previously ## 4.3)

<mark>Editor’s Note: This clause shall depict reference architectural patterns of products in this category, focusing on the architecture of the product itself and not the product as part of its operational environment or a larger ecosystem. The goal is to clearly indicate components, RDPS and their inter-relationships.</mark>

<mark>Editor’s Note: If the product category consists of multiple distinct product types, the reference architecture for each product type shall be drawn up separately for maximum clarity.</mark>

<mark>Editor’s Note: The diagram(s) shall be clearly labeled and accompanied by a short description of the main flows and components.</mark>

### 4.2.1 Product overview

(previously ### 4.3.1)

As a complete product, a Virtual Private Network includes, at minimum, VPN software capable of establishing a secure encrypted tunnel between two or more devices.

In consumer deployments, the most common state-of-the-art implementation is a product that provides a secure tunnel to one or more servers—usually managed by the manufacturer as “exit nodes”—which then route traffic to its originally intended destination, typically on a public network like the Internet.
@@ -331,15 +317,13 @@ Some VPN products also provide management capabilities to network administrators

### 4.2.2 VPN client

(previously ### 4.3.2)

For the purpose of the current document, a VPN client is a software application responsible for connecting a single end-point (such as a computing device or home router) to servers operating as exit nodes. A VPN client typically uses authentication credentials provided by the manufacturer or administrator and input by the user to establish secure tunnel(s) to an aforementioned exit node running VPN server software.

After establishing a tunnel, the VPN client changes configuration of the host device operating system to facilitate connections to the private network—this can include changes to DNS configuration, firewall rules, routing table, etc. This configuration is tailored to the end-user, and may be based on a combination of local user or administrator preferences and policies configured by the VPN manufacturer. A VPN client could have an option to perform traffic validation prior to sending the data through the established secure tunnel  [\[i.13\]](#_ref_i.13).

### 4.2.3 VPN server, VPN gateway

(previously ### 4.3.3)
#### 4.2.3.1 Server & gateway responsibilities

While [clause 4.1](#41-product-functions) establishes that any node within a VPN network may dynamically fulfill various operational roles, the terms “VPN server” and “VPN gateway” are used to describe nodes primarily dedicated to aggregation, routing, and access control.

@@ -347,6 +331,10 @@ A **VPN server** is responsible for maintaining secure tunnels between multiple

A **VPN gateway** specifically fulfills the gateway role, acting as the secure bridge between the restricted-use VPN network and external networks, such as a private corporate intranet or the public internet.

#### 4.2.3.2 Server & gateway remote data processing

When VPNs are reliant on exit nodes operated by the manufactuer, those exit nodes make up an important part of the product architecture. They typically serve the same functions as any other server or gateway, but remain entirely under the control of the manufacturer instead of being deployed on their customers' infrastructure. Due to the fact that a VPN is unable to function without this manner of data processing, it is held to the same requirements as any other VPN server or gateway, in addition to the requirements laid out in Annex R.

## 4.3 Operational Environment

(previously ## 4.4)
@@ -361,8 +349,7 @@ A **VPN gateway** specifically fulfills the gateway role, acting as the secure b

(previously ### 4.4.1)

The physical environment a VPN product may be deployed in affects the applicable risks and enables potential risk transfers.
VPN products may be deployed in various different environments such as different physical devices as well as different physical networks.
The physical environment a VPN product may be deployed in affects the applicable risks and enables potential risk transfers. VPN products may be deployed in various different environments such as different physical devices as well as different physical networks.

There are various types of devices, but they all share that the firewall is managed by the underlying system and outside of the control of the VPN product.

@@ -418,24 +405,20 @@ VPN products often include or are used in concert with:

## 4.4 Distribution of Security Functions

(previously ## 4.5)

<mark>Editor's Note: The clause should explain how the security functions are distributed among the product and its environment, referencing as appropriate elements of the operational environment defined in prior clauses. This analysis is not limited to which security functions products expect to get but should also explain which functions they themselves provide.</mark>

### 4.5.1 Cybersecurity function distribution overview
### 4.4.1 Cybersecurity function distribution overview

This clause describes the two-way relationship where the VPN product both delegates risks and provides cybersecurity functionalities to other components in its ecosystem.

The cybersecurity of a VPN product is dependent on a chain of trust that spans across multiple components in its operational environment. Consequently, the VPN product delegates certain risks to other components while offering cybersecurity functionalities that mitigate different risks for those same components.

### 4.5.2 Cybersecurity Functionalities Offered to Integrated Components
### 4.4.2 Cybersecurity Functionalities Offered to Integrated Components

The VPN product offers the following cybersecurity functionalities to other components in its operational environment:

- **Secure Data Transport**: The primary function of a VPN is to create a secure, encrypted tunnel over an untrusted network. This functionality protects all network traffic originating from the client device or network from eavesdropping and other network-based attacks.
- **Controlled Network Access**: The VPN client acts as a cybersecurity gatekeeper for the remote network. This functionality protects the remote network by only allowing authenticated and authorized traffic to pass through.

### 4.5.3 Cybersecurity functions required from the environment
### 4.4.3 Cybersecurity functions required from the environment

The following risks are delegated by the VPN product to other components within its operational environment:

@@ -445,8 +428,6 @@ The following risks are delegated by the VPN product to other components within

## 4.5 Users

(previously ## 4.6)

To ensure that the cybersecurity requirements address the specific threats faced by different market segments, the users of VPN products are categorized into groups based on their operational needs, level of cybersecurity expertise, and risk profiles. This categorization considers both direct end-users and integrators, and prioritizes the privacy, safety, and accessibility of the product for all individuals. These user groups directly correspond to the Use Cases (UC) detailed in [clause 4.6](#46-use-cases):

- Everyday Consumers and Vulnerable Groups (Refers to UC-1, UC-2): This group represents the general public, specifically including vulnerable populations such as children and the elderly, as well as individuals with limited cybersecurity knowledge. Their primary needs include securing personal traffic on untrusted networks and obfuscating online activity to avoid tracking. This segment requires highly accessible, secure-by-default configurations that accommodate users with disabilities who may rely on assistive technology to operate the product securely.
@@ -457,8 +438,6 @@ To ensure that the cybersecurity requirements address the specific threats faced

## 4.6 Use Cases

(previously ## 4.7)

### 4.6.1 Introduction to Use Cases

This list of use cases is an informative resource to the manufacturer to simplify choosing a set of cybersecurity requirements. It is not an exhaustive list, and deployments may cross over more than one use.