Commit 1e9d54fb authored by Aki Braun's avatar Aki Braun
Browse files

[RDI 14] 5.2.4 TR-SCUD

parent d8db0a6e
Loading
Loading
Loading
Loading
+1 −4
Original line number Diff line number Diff line
@@ -202,7 +202,7 @@ The product shall be accompanied by documentation of the secure update methods f

The product shall provide a method of securely updating any software in the product via the product itself.

* Applicability: Product expected use is long enough to require updates
* Applicability: All products that include a software update mechanism.
* Reference: TR-SCUD
* Objective: Prevent exploitation of known vulnerabilities
* Preparation: Prepare an update for each part of the product that can be updated with a different version number from the currently installed product version
@@ -225,7 +225,6 @@ The product shall provide a method of automatically securely updating any softwa

The technical documentation provided with the product shall document that the operational environment shall provide a method of securely updating the product.

* Applicability: Product expected use is long enough to require updates
* Reference: TR-SCUD
* Objective: Prevent exploitation of known vulnerabilities
* Activities: Assess the documentation provided with the product
@@ -236,7 +235,6 @@ The technical documentation provided with the product shall document that the op

The technical documentation provided with the product shall document that the operational environment shall provide a method of automatically securely updating the product with an option for the product to be configured to disable automatic updates.

* Applicability: Product expected use is long enough to require updates
* Reference: TR-SCUD
* Objective: Prevent exploitation of known vulnerabilities
* Activities: Assess the documentation provided with the product
@@ -249,7 +247,6 @@ The technical documentation provided with the product shall document that the op

Updates for the product are cryptographically signed. The product shall verify the signature before installation in order to mitigate the installation of tampered and/or modified updates.

* Applicability: Product expected use is long enough to require updates
* Reference: TR-SCUD
* Objective: Prevent the installation of modified updates.
* Activities: For each part of the product that can be updated, attempt installation of: