Commit 3b9597b7 authored by Aki Braun's avatar Aki Braun
Browse files

Edit Annex R for application to EN 304 620

parent 4c4c2346
Loading
Loading
Loading
Loading
+2 −1
Original line number Diff line number Diff line
@@ -358,7 +358,7 @@ A **VPN gateway** specifically fulfills the gateway role, acting as the secure b

#### 4.2.4.2 Server & gateway remote data processing

When VPNs are reliant on servers, gateways, or “exit nodes” operated by the manufacturer, those operations make up an important part of the product architecture. These typically serve the same functions as any other server or gateway, but remain entirely under the control of the manufacturer instead of being deployed on customer infrastructure. Due to the fact that a VPN is unable to function without this manner of data processing, it is held to the same requirements as any other VPN server or gateway, in addition to the requirements laid out in Annex R.
When VPNs are reliant on servers, gateways, or “exit nodes” operated by the manufacturer, those operations make up an important part of the product architecture. These typically serve the same functions as any other server or gateway, but remain entirely under the control of the manufacturer instead of being deployed on customer infrastructure. Where the product relies on a remote data processing solution (RDPS) for the provision or support of one or more product functions, such reliance introduces a product-facing RDPS boundary between the local product side and the RDPS side. RDPS-side VPN servers and gateways are held to the same requirements as any other VPN server or gateway, in addition to the requirements laid out in Annex R.

### 4.2.5 Management server

@@ -1438,6 +1438,7 @@ Table { seq tab }: Mapping of risks to requirements
|    REQ-SSD-05 (MI-IMSL) |      |      |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |
|    REQ-SSD-06 (MI-SCFS) |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
|    REQ-KEV-02 (MI-KEVT) |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
|              REQ-SSD-07 |  x   |  x   |  x   |  x   |  x   |      |  x   |
|  REQ-SBD-02 (MI-CONF-5) |  x   |  x   |  x   |  x   |  x   |      |  x   |
|     REQ-SU-02 (MI-KEVD) |  x²  |  x   |  x   |  x   |  x   |      |  x   |
|     REQ-SU-03 (MI-KEVA) |  x²  |  x   |  x   |      |      |      |  x   |
+25 −0
Original line number Diff line number Diff line
@@ -123,6 +123,30 @@ This requirement applies to products that are implemented in a compiled programm
* UC-6: required
* UC-7: required

### 5.2.7 REQ-SSD-07 Applicability of Annex R

##### 5.2.7.1 Requirement

Where the product relies on a remote data processing solution (RDPS) for the provision or support of one or more product functions, the product shall satisfy the applicable requirements specified in Annex R.

> NOTE: Annex R specifies supplementary requirements for the product-facing RDPS _boundary_ and does not replace the requirements applicable to the product _function_ as such.

##### 5.2.7.2 Applicability

This requirement applies to all products which provide any manner of RDPS, including 

* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: not required
* UC-7: not required if product does not require RDPS for the provision or support of any product function

#### 5.2.7.3 Guidance

This requirement does not apply to UC-6 because by definition that use case does not utilize any RDPS. If a product requires RDPS to fulfill any product function, it does not fall under UC-6.

### 5.2.N Mapping of requirements to use cases

|         Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
@@ -132,6 +156,7 @@ This requirement applies to products that are implemented in a compiled programm
| REQ-SSD-04 (MI-BTIN) |      |      |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |
| REQ-SSD-05 (MI-IMSL) |      |      |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |
| REQ-SSD-06 (MI-SCFS) |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
|           REQ-SSD-07 |  x   |  x   |  x   |  x   |  x   |      |  x   |

¹ REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) or REQ-SSD-05 (MI-IMSL) apply

+4 −0
Original line number Diff line number Diff line
@@ -222,6 +222,10 @@ Otherwise FAIL
* Output of binary analysis tools demonstrating the presence of exploit mitigations
* Documentation of exceptions

### 6.2.7 REQ-SSD-07 Applicability of Annex R

See annex R.5 for full assessment criteria.

## 6.3 No known exploitable vulnerabilities

### 6.3.1 Overview
+215 −1672

File changed.

Preview size limit exceeded, changes collapsed.