Commit 51ba3692 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Add documentation of risk transfer for denial of service to AVAI

parent bef03438
Loading
Loading
Loading
Loading
+8 −1
Original line number Diff line number Diff line
@@ -1009,7 +1009,14 @@ The product and supporting remote data processing services shall implement mecha

#### 5.2.19.7 MI-DOST: Document risk transfer to operational environment for denial of service

> TODO: Write mitigation documenting that the operational environment must provide denial of service protection, such as an external or internal firewall, fair queueing or filtering be the OS, a proxy, etc.
The product shall be accompanied by documentation informing the user that denial of service protection must be provided by the environment, in a form appropriate for a typical user for the intended purpose and reasonably foreseeable use and misuse of the product.

  * Reference: TR-AVAI
  * Objective: Maintain service availability during denial of service attacks
  * Preparation: None
  * Activities: Examine documentation
  * Verdict: Documentation exists and is appropriate to the typical user => PASS, otherwise FAIL
  * Evidence: Documentation, analysis of documentation, documentation of intended purpose

> TODO-HAS: delete below template before sending