Verified Commit 1f593053 authored by Aki Braun's avatar Aki Braun
Browse files

Add some more risk factors, provide clarity

parent 677edf32
Loading
Loading
Loading
Loading
+29 −20
Original line number Diff line number Diff line
@@ -412,41 +412,50 @@ This list of use cases is an informative resource to the manufacturer to simplif

The risk factors identified by the risk assessment in Annex C are grouped into risk categories and assigned unique identifiers below.

* Installation environment
  * **INS-L-0** Manufacturer has full control of operating system, i.e. remote data processing
  * **INS-L-1** Customer is known to manufacturer and can be expected to keep operating system up-to-date
  * **INS-L-1** Customer is not known to manufacturer, though other aspects of operating system can be predicted
  * **INS-L-0** Software is freely available for install in operating systems that may be customised or otherwise unpredictable

* Users with private network access
  * **USR-L-0** Restricted to limited users with managed devices and strong cybersecurity background
  * **USR-L-1** Restricted to devices fully managed by enterprise MDM
  * **USR-L-2** Accessible by user-controlled hardware with a fully preconfigured VPN client
  * **USR-L-3** Accessible by user-controlled hardware with user-selected VPN client

* Client configuration
  * **CFG-L-0** Client is fully preconfigured by enterprise IT, remote end-points and public keys updated by MDM 
  * **CFG-L-1** Client has limited user configuration options, such as choosing a region to connect to 
  * **CFG-L-2** End user is provided clear configuration instructions and client software is supplied directly by manufacturer or MDM
  * **CFG-L-3** End user is provided configuration information for any protocol-appropriate client

* Client authorisation
  * **AUT-L-0** Client requires multi-factor authentication
  * **AUT-L-1** Restricted to devices fully managed by enterprise MDM
  * **AUT-L-2** Accessible by user-controlled hardware with a fully preconfigured VPN client
  * **AUT-L-3** Accessible by user-controlled hardware with user-selected VPN client

* Users with administrative access
  * **USR-L-2** Accessible by end user-controlled hardware

* End-point configuration
  * **CFG-L-0** End-point is fully preconfigured by enterprise IT, remote end-points and public keys updated by MDM 
  * **CFG-L-1** End-point has limited user configuration options, such as choosing a region to connect to
  * **CFG-L-2** End user is provided clear configuration instructions and software is supplied directly by manufacturer or MDM
  * **CFG-L-3** End user is provided configuration information for any protocol-appropriate software to connect to the network

* End-point authorisation
  * **AUT-L-0** Customer uses third party identity provider
  * **AUT-L-1** TK

* Method of administrator access
  * **ADM-L-0** Restricted to limited IT professionals with a physical presence on the private network
  * **ADM-L-N** TK a description of a scenario where the VPN is entirely cloud-based so admin _cannot_ have a physical presence
  * **ADM-L-N** Administrators can access VPN management portal via the VPN
  * **ADM-L-1** Administrators access VPN management portal via a separate secure network
  * **ADM-L-2** Administrators can access VPN management portal via the VPN

* Physical access to data processing
  * **PHY-L-N**
  * **PHY-L-N**
  * **PHY-L-N**

### 4.X.1 Mapping of use cases to risk factors and security levels
* Node exposure to a public network
  * **PUB-L-0** Node is always behind a firewall on a private network and does not move
  * **PUB-TK-1** Node is in the DMZ? Is that a thing people do?
  * **PUB-L-2** Node does not maintain a consistent location and connects directly to a public network (not through a firewall)

  
### 4.X.1 Mapping of use cases to risk factors and security profiles

| Use case | USR | CFG | AUT | ADM | Sec Lev |
|----------|-----|-----|-----|-----|---------|
| UC-TK-1  | L-0 | L-0 | L-1 | L-0 | SC-TK-1 |

## 4.X Security levels
## 4.X Security profiles

> List the security levels and the use cases that correspond to them.