Verified Commit 4c4c2346 authored by Aki Braun's avatar Aki Braun
Browse files

Editorial: whitespace

parent 29a41b5f
Loading
Loading
Loading
Loading
+4 −2
Original line number Diff line number Diff line
@@ -204,7 +204,8 @@ For the purposes of the present document, the terms given in Regulation (EU) 202

> NOTE: This includes cases where that product provides access from a restricted-use logical computer network to the public internet.

**cryptographic mechanism**: security-related procedure using cryptography
**cryptographic mechanism**
: security-related procedure using cryptography

> NOTE 1: The term “cryptographic mechanism” is used as an umbrella term covering the categories used in the ECCG Agreed Cryptographic Mechanisms (ACM) catalogue [\[1\]](#_ref_1), including cryptographic algorithms, primitives, schemes, protocols, protocol profiles, cipher suites, modes of operation, constructions and parameter sets.

@@ -212,7 +213,8 @@ For the purposes of the present document, the terms given in Regulation (EU) 202

> NOTE 3: A cryptographic mechanism can be specified at different levels of abstraction. For example, AES is a cryptographic primitive, AES-GCM is a mode of operation / authenticated encryption construction, TLS 1.3 is a protocol, a TLS 1.3 restricted cipher-suite profile is a protocol profile, and TLS\_AES\_128\_GCM\_SHA256 is a cipher suite.

**cryptographic property**: property provided or supported by a cryptographic mechanism
**cryptographic property**
: property provided or supported by a cryptographic mechanism

> NOTE 1: Cryptographic properties include, for example, confidentiality, integrity, authenticity, entity authentication, message authentication, key establishment, key confirmation, replay protection, collision resistance, second-preimage resistance, pre-image resistance, signature unforgeability, non-repudiation, forward secrecy and password-verifier protection. Where relevant, a cryptographic property can be expressed using a formal cryptographic notion, for example IND-CPA, IND-CCA, IND-CCA2, EUF-CMA, SUF-CMA or authenticated key exchange security.

+1 −1
Original line number Diff line number Diff line
@@ -2,7 +2,7 @@

The technical requirements of the present document apply under the product context described in [clause 4](#product-context), which shall be in accordance with its intended use. The product shall comply with all applicable technical requirements of the present document at all times when operating in such a product context.

Not all requirements are universally applicable: The applicability of requirements may be based on use cases described in [clause 4.6](#use-cases) or specific capabilities of the product. Each requirement clearly indicates its applicability, and all requirements are mapped to use cases in [annex B](#annex-b-informative-security-analysis). The applicability of requirements is based on the security analysis in [annex B](#annex-b-informative-security-analysis), using the product assets and risk factors derived from the characteristics of each use case.
Not all requirements are universally applicable: The applicability of requirements may be based on use cases described in [clause 4.6](#use-cases) or specific capabilities of the product. Each requirement clearly indicates its applicability, and all requirements are mapped to use cases in [annex B](#annex-b-informative-security-analysis). The applicability of requirements is based on the security analysis in [annex B](#annex-b-informative-security-analysis), using the [product assets](#b.1-assets) and [risk factors](#b.2-risk-factors) derived from the characteristics of each use case.

Some risks may be transferred partially or fully to other components of the system or the user of the product. When that is the case, mitigations that transfer the risk will be included as an option to fulfill a cybersecurity requirement, depending on the use case and risk factors.