Verified Commit 186f002a authored by Aki Braun's avatar Aki Braun
Browse files

Replace "manufacturer" whre appropriate

Sometimes it's RDPS, sometimes it's technical documentation
parent a0fb57ed
Loading
Loading
Loading
Loading
+5 −5
Original line number Diff line number Diff line
@@ -1443,7 +1443,7 @@ The VPN product should be able to operate without a wide set of permissions—eg

This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (k).

In addition to protecting data transiting the VPN from typical attacks, it is important for VPN manufacturers to ensure their own collection of data is not also an attack vector. In the event of a successful breach of a VPN manufacturer, attackers cannot exfiltrate data that does not exist.
In addition to protecting data transiting the VPN from typical attacks, it is important for the collection of data via RDPS is not also an attack vector. In the event of a successful breach of a VPN manufacturer, attackers cannot exfiltrate data that does not exist.

### 5.13.2 REQ-EMM-02 (MI-NUTI-1) Policy-driven traffic exclusion

@@ -1557,7 +1557,7 @@ The minium scope of cybersecurity-relevant events logged by the VPN client may i
* changes applied by the VPN client to the host system's network configuration technically relevant for the VPN service provision, or
* software update successes or failures.

Products are expected to exclude from logs any confidential information such as Personal Data, network traffic content, connection metadata (e.g., destination IPs, DNS queries), secrets, or credentials. Logs are to be retained locally on the endpoint; to comply with data minimization requirements, logs are not to be transmitted to the remote data processing solutions of the VPN manufacturer by default. Transmission of local logs to the manufacturer (e.g., for technical support or troubleshooting) is unacceptable without explicit, informed user authorization (e.g. explicit opt-in).
Products are expected to exclude from logs any confidential information such as Personal Data, network traffic content, connection metadata (e.g., destination IPs, DNS queries), secrets, or credentials. Logs are to be retained locally on the endpoint; to comply with data minimization requirements, logs are not to be transmitted to the product’s remote data processing solutions by default. Transmission of local logs to remote data processing solutions (e.g., for technical support or troubleshooting) is unacceptable without explicit, informed user authorization (e.g. explicit opt-in).

### 5.14.2 REQ-LOG-02 (MI-LOGG-1) Logging

@@ -1585,7 +1585,7 @@ The minium scope of cybersecurity-relevant events logged by the VPN client may i
* changes applied by the VPN client to the host system's network configuration technically relevant for the VPN service provision, or
* software update successes or failures.

The log messages shall not include any confidential information such as Personal Data, network traffic content, connection metadata (e.g., destination IPs, DNS queries), secrets, or credentials. These logs shall be retained locally on the endpoint. To comply with data minimization requirements, the VPN client shall not transmit these logs to the remote data processing solutions of the VPN manufacturer by default. Transmission of local logs to the manufacturer (e.g., for technical support or troubleshooting) shall require explicit, informed user authorization (e.g. explicit opt-in).
The log messages shall not include any confidential information such as Personal Data, network traffic content, connection metadata (e.g., destination IPs, DNS queries), secrets, or credentials. These logs shall be retained locally on the endpoint. To comply with data minimization requirements, the VPN client shall not transmit these logs to the product’s remote data processing solutions by default. Transmission of local logs to the RDPS (e.g., for technical support or troubleshooting) shall require explicit, informed user authorization (e.g. explicit opt-in).

### 5.14.3 REQ-LOG-03 (MI-LOGG-2) Remote Logging

@@ -1614,7 +1614,7 @@ Logging output is expected to take care to not accidentally include a secret as

#### 5.14.4.1 Requirement

1. **REQ-LOG-04 (MI-LOGG-3)-1** The remote data processing solutions of the VPN manufacturer shall technically enforce a strict “no-logs” policy, and
1. **REQ-LOG-04 (MI-LOGG-3)-1** The product’s remote data processing solutions shall technically enforce a strict “no-logs” policy, and
2. **REQ-LOG-04 (MI-LOGG-3)-2** the remote data processing solutions shall ensure that no information about the user's network traffic is persistently stored; this includes Personal Data, the client's source IP, or connection metadata, such as destination IPs and other plaintext connection information (e.g., DNS queries, Ports or SNI Headers).

#### 5.14.4.2 Applicability
@@ -1711,7 +1711,7 @@ This requirement applies to products with the capability for the user to write d

#### 5.15.5.2 Applicability

This requirement applies to products with the capability for the user to write data and/or settings, and manufacturer support of exporting of that data to an external file. This requirement is strictly applicable to use cases where an IT professional or advanced user can reasonably be expected to administer the product.
This requirement applies to products with the capability for the user to write data and/or settings, and product support of exporting of that data to an external file. This requirement is strictly applicable to use cases where an IT professional or advanced user can reasonably be expected to administer the product.

Of the above described products, this requirement applies to products that fall within the following use cases

+7 −7
Original line number Diff line number Diff line
@@ -1290,7 +1290,7 @@ None.
PASS if **any** of the following are fulfilled for **each** test:

* DNS connections to well-known public DNS providers are blocked, or
* the user is notified that some software on the operating system could be using encrypted DNS protocols with servers that do not belong to the VPN manufacturer.
* the user is notified that some software on the operating system could be using encrypted DNS protocols which conflict with the product's DNS-based routing configuration.

Otherwise FAIL

@@ -1596,7 +1596,7 @@ None.
#### 6.9.2.3 Activities

1. Capture all packets during a typical hour of use.
2. Document all data sent to the VPN manufacturer.
2. Document all data sent to the product's RDPS.
3. Label all data as Personal Data or not.
4. Document for all Personal Data:
   * if it is kept,
@@ -1634,7 +1634,7 @@ Retrieve internal policy from VPN manufacturer.
#### 6.9.3.3 Activities

1. Capture all packets during a typical hour of use.
2. Document all data sent to the VPN manufacturer.
2. Document all data sent to the product's RDPS.
3. Label any Personal Data included in packet capture.

#### 6.9.3.4 Verdict
@@ -1644,14 +1644,14 @@ PASS if **all** of the following are fulfilled:
* All labelled Personal Data collected is either:
   * strictly necessary for the confidentiality or availability of the product as outlined in the internal policy and intended use of the VPN manufacturer or
   * Personal Data collected is explicitly justified for authentication, access control, or subscription management.
* No personal data is collected from the user’s VPN tunnelling and routing functionality which is not indented for the VPN manufacturer
* No personal data is collected from the user’s VPN tunnelling and routing functionality which is not indented for the VPN manufacturer.

Otherwise FAIL

#### 6.9.3.5 Evidence

* Packet capture
* Manufacturer's documentation justifying the necessity of any transmitted data
* Technical documentation justifying the necessity of any transmitted data

### 6.9.4 REQ-DM-04 (MI-NPER-3) Minimize Personal Data required service provisioning and payment

@@ -1669,7 +1669,7 @@ Obtain a fresh installation of the VPN product.
2. Select the options that require the least Personal Data
3. Recording all data entered
4. Examine the data entered looking for Personal Data
5. Review the manufacturer's provided justification for the necessity of this data in relation to providing the service, processing payment or managing the subscription.
5. Review the provided documentation of justification for the necessity of this data in relation to providing the service, processing payment or managing the subscription.

#### 6.9.4.4 Verdict

@@ -2112,7 +2112,7 @@ Monitoring and recording cybersecurity-relevant events.

#### 6.14.2.2 Preparation

Review the manufacturer's documentation to confirm the scope of cybersecurity-relevant internal events implemented in the logging mechanism.
Review the technical documentation to confirm the scope of cybersecurity-relevant internal events implemented in the logging mechanism.

#### 6.14.2.3 Activities