@@ -331,7 +331,7 @@ The following types of products have reduced or varied requirements under Regula
### 4.3.1 Product overview
As a holistic product, a Virtual Private Network includes, at minimum, VPN client or server software running in two or more locations which establish a secure encrypted tunnel to communicate. In addition to software necessary for establishing the communication tunnels, VPN products provide management capabilities to network administrators: user and group management, access control, logging and monitoring.
As a holistic product, a Virtual Private Network includes, at minimum, VPN software capable of establishing a secure encrypted tunnel on two or more devices. VPN products also provide management capabilities to network administrators: user and group management, access control, logging and monitoring.

@@ -349,7 +349,7 @@ In a mesh network, clients and gateways establish direct tunnels between each ot
### 4.2.3 VPN client
VPN client is a piece of software responsible for connecting a single endpoint to a private network. It typically uses authentication credentials provided by the end-user to establish secure tunnel(s) to other participant(s) of the network: a VPN server, or other VPN clients and gateways (in case of a mesh network).
VPN client is a piece of software responsible for connecting a single end-point to a private network. It typically uses authentication credentials provided by the end-user to establish secure tunnel(s) to other participant(s) of the network: a VPN server, or other VPN clients and gateways (in case of a mesh network).
After establishing a tunnel, the VPN client changes configuration of the operating system to facilitate connections to the private network - this can include changes to DNS configuration, firewall rules, routing table, etc. This configuration is tailored to the end-user, and is based on a combination of local user preferences and policies configured centrally by the network administrator.
@@ -376,7 +376,7 @@ In VPNs using a hub-and-spoke topology, management server is often implemented a
This list of use cases is an informative resource to the manufacturer to simplify choosing a set of security requirements. Each use case is mapped to a security level, which is a collection of risks and the security requirements necessary to mitigate them.
***UC-0** ~~Microenterprise, hobbyist~~
* (this type of user is likely using VPN software that is preinstalled on a router or modem, not offered as a product with digital elements on the open market. out of scope.)
* (this type of user is likely using VPN software that is preinstalled on a router or modem, not offered as a product with digital elements on the EU market. out of scope.)
***UC-1** Small enterprise, small not-for-profit organisation
* limited or no full-time IT/network administration
@@ -391,12 +391,12 @@ This list of use cases is an informative resource to the manufacturer to simplif
***UC-3** Large enterprise, university, non-classified government entities
* distinct network and IT teams
* experienced IT professionals managing configuration
* connecting distributed workforce and multiple locations with distinct private networks
*values control over configuration and management
* connecting distributed workforce and multiple locations with distinct private networks (including data centres and cloud)
*expects fine-grained control of configuration and management
***UC-4** Hospitals, financial institutions, certain newspapers and broadcasters
* likely targets of organised bad actors
* evade surveillance
*establish tunnel to evade surveillance
* increased security needs
## 4.5 Risk factors
@@ -432,7 +432,7 @@ The risk factors identified by the risk assessment in Annex C are grouped into r
***USR-L-3** Accessible by user-controlled hardware with user-selected VPN client
* Client configuration
***CFG-L-0** Client is fully preconfigured by enterprise IT, remote endpoints and public keys updated by MDM
***CFG-L-0** Client is fully preconfigured by enterprise IT, remote end-points and public keys updated by MDM
***CFG-L-1** Client has limited user configuration options, such as choosing a region to connect to
***CFG-L-2** End user is provided clear configuration instructions and client software is supplied directly by manufacturer or MDM
***CFG-L-3** End user is provided configuration information for any protocol-appropriate client
@@ -459,7 +459,6 @@ The risk factors identified by the risk assessment in Annex C are grouped into r
|----------|-----|-----|-----|-----|---------|
| UC-TK-1 | L-0 | L-0 | L-1 | L-0 | SC-TK-1 |
## 4.6 Security levels
> List the security levels and the use cases that correspond to them.
@@ -476,7 +475,6 @@ Each security level will consist of the security requirements necessary to mitig
> List the essential functions of the product, including:
@@ -547,7 +545,7 @@ The physical hardware the VPN product is using may be:
### 4.7.2 Digital environment
VPNs can be expected to operate in a network environment alongside other Important PwDEs such as Identity Access Management, Network Interfaces, Routers, and Firewalls. Manufacturers shall harden VPN attack surfaces against potential attack vectors from compromised PwDEs, but in particular those considered Important and Critical. See clause TK for further information about the relationship between VPNs and related software.
VPNs can be expected to operate in a network environment alongside other Important PwDEs such as Identity Access Management, Network Interfaces, Routers, Firewalls, and SIEM systems. Manufacturers shall harden VPN attack surfaces against potential attack vectors from compromised PwDEs, but in particular those considered Important and Critical. See clause TK for further information about the relationship between VPNs and related software.
A VPN requires an existing physical or virtual network whose resources it can use. The underlying network must provide the functions necessary to connect to at least one node of the VPN.