Loading EN-304-620.md +21 −21 Original line number Diff line number Diff line Loading @@ -900,11 +900,11 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-CON-15 (MI-CDST) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-CON-15 (MI-CDST) ### B.4.4 TH-KEVU: Known exploitable vulnerabilities Loading @@ -925,7 +925,7 @@ Attacker may use known exploitable vulnerabilities in the product implementation | FUN is 2 or NUM is 2 | High | UC-3, UC-5, UC-6 | | all others | Medium | UC-1, UC-2, UC-4, UC-7 | All mitigations from TH-UEVU apply (using that requirement's risk formula), in addition to: All mitigations from TH-UEVU apply (using that requirement's risk formula), **in addition to**: Mitigations for Likelihood: Loading @@ -950,11 +950,11 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-CON-15 (MI-CDST) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-CON-15 (MI-CDST) ### B.4.5 TH-UEAC: Unauthorized endpoint access Loading Loading @@ -1034,11 +1034,11 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-INT-05 (MI-NUTI-2) OR REQ-INT-06 * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-INT-05 (MI-NUTI-2) OR REQ-INT-06 ### B.4.7 TH-MITM: Machine-in-the-middle Loading Loading @@ -1130,10 +1130,10 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) ### B.4.9 TH-PLNS: Transmitting sensitive data in the clear in a single endpoint VPN Loading Loading @@ -1180,10 +1180,10 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) ### B.4.10 TH-PLNM: Transmitting sensitive data in the clear in multi-endpoint VPN Loading Loading @@ -1230,10 +1230,10 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-03 (MI-LOGG-2) ### B.4.11 TH-LDEL: Unknown compromise of endpoint Loading @@ -1257,10 +1257,10 @@ Attacker may compromise endpoint without the user learning of it. Mitigations for Likelihood: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * If PRI is 0: REQ-LOG-03 (MI-LOGG-2) Mitigations for Impact: Loading Loading @@ -1317,13 +1317,13 @@ Mitigations for Impact: * Medium to Low: * REQ-CON-15 (MI-CDST) * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-AAC-04 (MI-AUTH-3) * REQ-INT-03 (MI-CONF-2) * REQ-CON-15 (MI-CDST) * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * If PRI is 0: REQ-LOG-03 (MI-LOGG-2) ### B.4.13 TH-CNFM: Access to assets via configuration errors in a multi-endpoint VPN Loading Loading @@ -1365,14 +1365,14 @@ Mitigations for Impact: * Medium to Low: * REQ-AAC-04 (MI-AUTH-3) * REQ-CON-15 (MI-CDST) * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-AAC-04 (MI-AUTH-3) * REQ-AAC-05 (MI-AUTH-4) * REQ-AAC-06 (MI-AUTH-5) * REQ-CON-15 (MI-CDST) * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-03 (MI-LOGG-2) ### B.4.14 TH-META: Compromise of privacy due to metadata and traffic analysis Loading Loading @@ -1528,10 +1528,10 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) ## B.5 Mapping of use cases to risk factors Loading clauses/5.Requirements.md +4 −0 Original line number Diff line number Diff line Loading @@ -1450,6 +1450,8 @@ Products with the capability to transmit logs to remote data processing solution #### 5.14.TK.2 Applicability This requirement applies to the subset of products within the indicated use cases where RF-PRI is > 0. * UC-1: not required * UC-2: not required * UC-3: not required Loading @@ -1467,6 +1469,8 @@ Products with the capability to transmit logs to remote data processing solution #### 5.14.2.2 Applicability This requirement applies to the subset of products within the indicated use cases where RF-PRI is 0. * UC-1: required * UC-2: required * UC-3: required Loading Loading
EN-304-620.md +21 −21 Original line number Diff line number Diff line Loading @@ -900,11 +900,11 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-CON-15 (MI-CDST) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-CON-15 (MI-CDST) ### B.4.4 TH-KEVU: Known exploitable vulnerabilities Loading @@ -925,7 +925,7 @@ Attacker may use known exploitable vulnerabilities in the product implementation | FUN is 2 or NUM is 2 | High | UC-3, UC-5, UC-6 | | all others | Medium | UC-1, UC-2, UC-4, UC-7 | All mitigations from TH-UEVU apply (using that requirement's risk formula), in addition to: All mitigations from TH-UEVU apply (using that requirement's risk formula), **in addition to**: Mitigations for Likelihood: Loading @@ -950,11 +950,11 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-CON-15 (MI-CDST) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-CON-15 (MI-CDST) ### B.4.5 TH-UEAC: Unauthorized endpoint access Loading Loading @@ -1034,11 +1034,11 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-INT-05 (MI-NUTI-2) OR REQ-INT-06 * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-INT-05 (MI-NUTI-2) OR REQ-INT-06 ### B.4.7 TH-MITM: Machine-in-the-middle Loading Loading @@ -1130,10 +1130,10 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) ### B.4.9 TH-PLNS: Transmitting sensitive data in the clear in a single endpoint VPN Loading Loading @@ -1180,10 +1180,10 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) ### B.4.10 TH-PLNM: Transmitting sensitive data in the clear in multi-endpoint VPN Loading Loading @@ -1230,10 +1230,10 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-03 (MI-LOGG-2) ### B.4.11 TH-LDEL: Unknown compromise of endpoint Loading @@ -1257,10 +1257,10 @@ Attacker may compromise endpoint without the user learning of it. Mitigations for Likelihood: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * If PRI is 0: REQ-LOG-03 (MI-LOGG-2) Mitigations for Impact: Loading Loading @@ -1317,13 +1317,13 @@ Mitigations for Impact: * Medium to Low: * REQ-CON-15 (MI-CDST) * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-AAC-04 (MI-AUTH-3) * REQ-INT-03 (MI-CONF-2) * REQ-CON-15 (MI-CDST) * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * If PRI is 0: REQ-LOG-03 (MI-LOGG-2) ### B.4.13 TH-CNFM: Access to assets via configuration errors in a multi-endpoint VPN Loading Loading @@ -1365,14 +1365,14 @@ Mitigations for Impact: * Medium to Low: * REQ-AAC-04 (MI-AUTH-3) * REQ-CON-15 (MI-CDST) * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-AAC-04 (MI-AUTH-3) * REQ-AAC-05 (MI-AUTH-4) * REQ-AAC-06 (MI-AUTH-5) * REQ-CON-15 (MI-CDST) * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-03 (MI-LOGG-2) ### B.4.14 TH-META: Compromise of privacy due to metadata and traffic analysis Loading Loading @@ -1528,10 +1528,10 @@ Mitigations for Likelihood: Mitigations for Impact: * Medium to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) * High to Low: * REQ-LOG-02 (MI-LOGG-1) * REQ-LOG-TK (MI-LOGG-1) OR REQ-LOG-02 (MI-LOGG-1) ## B.5 Mapping of use cases to risk factors Loading
clauses/5.Requirements.md +4 −0 Original line number Diff line number Diff line Loading @@ -1450,6 +1450,8 @@ Products with the capability to transmit logs to remote data processing solution #### 5.14.TK.2 Applicability This requirement applies to the subset of products within the indicated use cases where RF-PRI is > 0. * UC-1: not required * UC-2: not required * UC-3: not required Loading @@ -1467,6 +1469,8 @@ Products with the capability to transmit logs to remote data processing solution #### 5.14.2.2 Applicability This requirement applies to the subset of products within the indicated use cases where RF-PRI is 0. * UC-1: required * UC-2: required * UC-3: required Loading