Verified Commit 54384bab authored by Marvin Petzolt's avatar Marvin Petzolt Committed by Aki Braun
Browse files

Revertes assessment criteria and smaller fixes

parent 7282fee4
Loading
Loading
Loading
Loading
+23 −18
Original line number Diff line number Diff line
@@ -821,9 +821,9 @@ Description: How publicly accessible the underlying network is.

Rationale: The more unrestricted the access to underlying network is, the more likely a threat actor can send packets to the device.

* **[NET-L-0]** Foreseeable use is in an isolated private network
* **[NET-L-1]** Foreseeable use is in a private network with filtered connection to public network
* **[NET-L-2]** Foreseeable use is in a public network
* **[NET-0]** Foreseeable use is in an isolated private network
* **[NET-1]** Foreseeable use is in a private network with filtered connection to public network
* **[NET-2]** Foreseeable use is in a public network

## B.3 Assumptions

@@ -889,13 +889,12 @@ Attacker may use unknown exploitable vulnerabilities in the product implementati
Mitigations for Likelihood:

* Medium to Low:
  * REQ-SSD-04 (MI-BTIN)
  * REQ-SSD-03 (MI-FZ95) OR REQ-SSD-04 (MI-BTIN)
  * REQ-MAS-02 (MI-CONF-4)

* High to Low:
  * REQ-SSD-03 (MI-FZ95) OR REQ-SSD-04 (MI-BTIN)
  * REQ-MAS-02 (MI-CONF-4)
  * REQ-EMM-02 (MI-NUTI-1)

Mitigations for Impact:

@@ -1118,7 +1117,7 @@ Mitigations for Likelihood:
  * REQ-CON-02 (MI-ROUT-1)
  * REQ-CON-03 (MI-ROUT-2)
  * REQ-CON-04 (MI-ROUT-3)
  * REQ-CON-05 (MI-ROUT-4)
  * if MSH is 2: REQ-CON-05 (MI-ROUT-4)
  * REQ-CON-07 (MI-DNSL-2)
  * REQ-CON-08 (MI-DNSL-3)
  * REQ-CON-09 (MI-DNSL-5)
@@ -1173,7 +1172,6 @@ Mitigations for Likelihood:
  * REQ-CON-02 (MI-ROUT-1)
  * REQ-CON-03 (MI-ROUT-2)
  * REQ-CON-04 (MI-ROUT-3)
  * REQ-CON-05 (MI-ROUT-4)
  * REQ-CON-14 (MI-CRYPT-1)
  * REQ-IM-02 (MI-EISO)

@@ -1212,6 +1210,8 @@ Mitigations for Likelihood:
  * REQ-AAC-03 (MI-AUTH-2)
  * REQ-CON-02 (MI-ROUT-1)
  * REQ-CON-14 (MI-CRYPT-1)
  * If MSH is 2: REQ-AAC-09 (MI-TRAF-5)
  * If MSH is 2: REQ-CON-05 (MI-ROUT-4)

* High to Low:
  * REQ-AAC-02 (MI-AUTH-1)
@@ -1220,11 +1220,11 @@ Mitigations for Likelihood:
  * REQ-AAC-05 (MI-AUTH-4)
  * REQ-AAC-06 (MI-AUTH-5)
  * REQ-AAC-08 (MI-AUTH-7)
  * If MSH is more than 0: REQ-AAC-09 (MI-TRAF-5)
  * If MSH is 2: REQ-AAC-09 (MI-TRAF-5)
  * REQ-CON-02 (MI-ROUT-1)
  * REQ-CON-03 (MI-ROUT-2)
  * REQ-CON-04 (MI-ROUT-3)
  * REQ-CON-05 (MI-ROUT-4)
  * If MSH is 2: REQ-CON-05 (MI-ROUT-4)
  * REQ-CON-14 (MI-CRYPT-1)

Mitigations for Impact:
@@ -1350,13 +1350,18 @@ Mitigations for Likelihood:

* Medium to Low:
  * REQ-SBD-02 (MI-CONF-5)
  * REQ-EMM-02 (MI-NUTI-1) OR (REQ-EMM-03 (MI-TRAF-2) AND REQ-EMM-04 (MI-TRAF-3) AND REQ-EMM-05 (MI-TRAF-4))
  * REQ-EMM-03 (MI-TRAF-2)
  * REQ-EMM-04 (MI-TRAF-3)
  * REQ-EMM-05 (MI-TRAF-4)
  * REQ-CON-12 (MI-IPV6-1)
  * REQ-CON-13 (MI-IPV6-2)

* High to Low:
  * REQ-EMM-02 (MI-NUTI-1)
  * REQ-SBD-02 (MI-CONF-5)
  * REQ-INT-05 (MI-NUTI-2) OR REQ-INT-06
  * REQ-EMM-03 (MI-TRAF-2)
  * REQ-EMM-04 (MI-TRAF-3)
  * REQ-EMM-05 (MI-TRAF-4)
  * REQ-CON-12 (MI-IPV6-1)
  * REQ-CON-13 (MI-IPV6-2)

@@ -1436,11 +1441,11 @@ Mitigations for Likelihood:

* Medium to Low:
  * REQ-DM-06 (MI-LOGG-X)
  * TODO - add Annex R requirements
  * REQ-SSD-07

* High to Low:
  * REQ-DM-06 (MI-LOGG-X)
  * TODO - add Annex R requirements
  * REQ-SSD-07

Mitigations for Impact:

@@ -1543,8 +1548,8 @@ Mitigations for Impact:
| UC-2     | Privacy conscious household | 1   | 1   | 1   | 1   | 1   | 0   | 1   | 1   | 2   | 1   | 0   | 0   | 2   |
| UC-3     | Journalist or activist      | 1   | 2   | 2   | 2   | 2   | 0   | 2   | 2   | 2   | 1   | 0   | 0   | 2   |
| UC-4     | Small organization          | 2   | 1   | 1   | 1   | 0   | 1   | 1   | 2   | 2   | 2   | 1   | 1   | 2   |
| UC-5     | Large enterprise            | 2   | 2   | 1   | 2   | 0   | 2   | 0   | 2   | 2   | 2   | 2   | 2   | 2   |
| UC-6     | Enterprise-owned VPN infra  | 1   | 2   | 1   | 2   | 0   | 2   | 1   | 0   | 0   | 2   | 2   | 2   | 2   |
| UC-5     | Large enterprise            | 2   | 2   | 1   | 2   | 0   | 2   | 0   | 2   | 2   | 2   | 1   | 2   | 2   |
| UC-6     | Enterprise-owned VPN infra  | 1   | 2   | 1   | 2   | 0   | 2   | 1   | 0   | 0   | 2   | 1   | 2   | 2   |
| UC-7     | Mesh network                | 2   | 1   | 1   | 1   | 1   | 1   | 1   | 1   | 2   | 2   | 2   | 1   | 2   |

## B.6 Risks not treated by the requirements
@@ -1669,7 +1674,9 @@ For each risk untreated by the product itself in any applicable use case, a corr
|                         |      |      |      |      |      |      |      |
|  REQ-MAS-02 (MI-CONF-4) |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
|                         |      |      |      |      |      |      |      |
|  REQ-EMM-02 (MI-NUTI-1) |      |      |  x   |  x   |  x   |  x   |  x   |
|  REQ-EMM-03 (MI-TRAF-2) |  x   |  x   |  x   |      |  x   |  x   |      |
|  REQ-EMM-04 (MI-TRAF-3) |  x   |  x   |  x   |      |  x   |  x   |      |
|  REQ-EMM-05 (MI-TRAF-4) |  x   |  x   |  x   |      |  x   |  x   |      |
|  REQ-EMM-03 (MI-TRAF-2) |  x   |  x   |  x   |      |  x†  |  x†  |      |
|  REQ-EMM-04 (MI-TRAF-3) |  x   |  x   |  x   |      |  x†  |  x†  |      |
|  REQ-EMM-05 (MI-TRAF-4) |  x   |  x   |  x   |      |  x†  |  x†  |      |
@@ -1689,11 +1696,9 @@ For each risk untreated by the product itself in any applicable use case, a corr
* x³ REQ-SU-05 (MI-SUVP) OR REQ-SU-06 (MI-SUAP) OR REQ-SU-08 (MI-SUOE) OR REQ-SU-09 (MI-SUAO)
* x⁴ applies where risk factor [RF-UAP](#b.2.13-rf-uap-consequences-of-unauthorized-access-to-private-network) is > 0
* x⁵ applies where risk factor [RF-MSH](#b.2.11-rf-msh-mesh-connectivity-offered) is 2
* x⁶ applies where risk factor [RF-MSH](#b.2.11-rf-msh-mesh-connectivity-offered) is > 0
* x⁷ REQ-INT-05 (MI-NUTI-2) OR REQ-INT-06
* x⁸ REQ-AP-04 (MI-DOST-1) OR (REQ-AP-02 (MI-FDRP) AND REQ-AP-03 (MI-LMEM))
* x⁹ REQ-AP-04 (MI-DOST-1) OR (REQ-AP-02 (MI-FDRP) AND REQ-AP-03 (MI-LMEM) AND REQ-AP-05 (MI-DOST-2))
* x† REQ-EMM-02 (MI-NUTI-1) OR (REQ-EMM-03 (MI-TRAF-2) AND REQ-EMM-04 (MI-TRAF-3) AND REQ-EMM-05 (MI-TRAF-4))
* x‡ applies where risk factor [RF-PRI](#b.2.12-rf-pri-consequences-of-compromise-of-privacy) is 0

# Annex K (normative): Generic requirements and assessment criteria for the use of state-of-the-art cryptography
+41 −24
Original line number Diff line number Diff line
@@ -195,13 +195,13 @@ The product shall implement automatic secure update before or during first use.

This requirement applies to the subset of products within the indicated use cases that have the capability to self-update, i.e. not distributed by an “app store” or package distribution platform that manages all updates.

* UC-1: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-2: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-3: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-4: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-5: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-6: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-7: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-7: required

### 5.5.4 REQ-SU-04 (MI-KEVE) Automatic secure update via operational environment before or during first use

@@ -211,17 +211,17 @@ The product shall implement secure update via the operational environment before

#### 5.5.4.2 Applicability

This requirement applies to the indicated use cases where network infrastructure is managed by professional network administrator in an enterprise environment.
This requirement applies to the subset of products within the indicated use cases where updates are managed by the operational environment and not by the product itself.

> NOTE: Enterprise customers may have a business need to either delay or force updates to any node with access to a private network.

* UC-1: not required
* UC-2: not required
* UC-3: not required
* UC-4: not required
* UC-5: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-6: not required
* UC-7: not required
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-7: required

### 5.5.5 REQ-SU-05 (MI-SUVP) Secure update via product

@@ -561,7 +561,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: not required
* UC-6: required
* UC-7: required

### 5.6.6 REQ-AAC-06 (MI-AUTH-5) Forced revocation of authorization of endpoints
@@ -582,7 +582,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: not required
* UC-6: required
* UC-7: required

### 5.6.7 REQ-AAC-07 (MI-AUTH-6) Brute force protection
@@ -624,7 +624,7 @@ A node shall only allow connections from authorized endpoints.
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: not required
* UC-6: required
* UC-7: required

### 5.6.9 REQ-AAC-09 (MI-TRAF-5) Fine-grain access control
@@ -757,7 +757,7 @@ The VPN traffic shall be encrypted using session keys generated and held only by

#### 5.7.6.1 Requirement

1. **REQ-CON-06 (MI-DNSL-1)-1** The VPN client shall prominently inform the user of the visibility of plaintext DNS queries outside the tunnel under the current configuration and the consequences in simple plain language, focusing on the potential risk and impact to the user of such handling and, where applicable, potential steps to resolve this risk, and
1. **REQ-CON-06 (MI-DNSL-1)-1** The VPN client shall prominently inform the user of the visibility of DNS queries outside the tunnel under the current configuration and the consequences in simple plain language, focusing on the potential risk and impact to the user of such handling and, where applicable, potential steps to resolve this risk, and
2. **REQ-CON-06 (MI-DNSL-1)-2** the product shall require the user to actively confirm having read the information before being able to use the VPN connection.

#### 5.7.6.2 Applicability
@@ -940,6 +940,22 @@ Depending on the data type and operational environment, the product shall protec
* UC-6: required
* UC-7: required

### 5.7.16 REQ-CON-16 Inform user of limits of privacy protection

#### 5.7.16.1 Requirement

The product shall inform the user of the limitations of any privacy protection.

#### 5.7.16.2 Applicability

* UC-1: not required
* UC-2: required
* UC-3: required
* UC-4: not required
* UC-5: not required
* UC-6: not required
* UC-7: required

### 5.7.N Mapping of requirements to use cases

|            Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
@@ -958,6 +974,7 @@ Depending on the data type and operational environment, the product shall protec
|  REQ-CON-13 (MI-IPV6-2) |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
| REQ-CON-14 (MI-CRYPT-1) |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
|    REQ-CON-15 (MI-CDST) |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
|              REQ-CON-16 |      |  x   |  x   |      |      |      |  x   |

## 5.8 Integrity protection

@@ -1075,7 +1092,7 @@ The product shall not collect data unnecessary for the operation of the product.

#### 5.9.2.1 Requirement

The product shall not collect Personal Data unless the collection is necessary for an intended purpose of the product, or the user or administrator has explicitly authorized it.
The product shall not collect Personal Data unless the collection is necessary for an intended purpose of the product, or the user has explicitly authorized it.

#### 5.9.2.2 Applicability

@@ -1148,7 +1165,7 @@ The VPN shall not store any Personal Data of the user on the VPN server, gateway
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: not required
* UC-4: required
* UC-5: not required
* UC-6: not required
* UC-7: required
+26 −0
Original line number Diff line number Diff line
@@ -1315,6 +1315,32 @@ Otherwise FAIL
* Logs or screenshots demonstrating the failure to read the data without authorization
* Documentation validating the encryption/hashing algorithms used

### 6.7.16 REQ-CON-16 Inform user of limits of privacy protection

#### 6.7.16.1 Objective

Privacy protection

#### 6.7.16.2 Preparation

Perform first install of product.

#### 6.7.16.3 Activities

Launch product.

#### 6.7.16.4 Verdict

PASS if **all** of the following are fulfilled:

* Initial onboarding provides information regarding boundaries of privacy protection.

Otherwise FAIL

#### 6.7.16.5 Evidence

* Screenshots

## 6.8 Integrity protection

### 6.8.1 Overview