@@ -195,13 +195,13 @@ The product shall implement automatic secure update before or during first use.
This requirement applies to the subset of products within the indicated use cases that have the capability to self-update, i.e. not distributed by an “app store” or package distribution platform that manages all updates.
* UC-1: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-2: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-3: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-4: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-5: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-6: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-7: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-7: required
### 5.5.4 REQ-SU-04 (MI-KEVE) Automatic secure update via operational environment before or during first use
@@ -211,17 +211,17 @@ The product shall implement secure update via the operational environment before
#### 5.5.4.2 Applicability
This requirement applies to the indicated use cases where network infrastructure is managed by professional network administrator in an enterprise environment.
This requirement applies to the subset of products within the indicated use cases where updates are managed by the operational environment and not by the product itself.
> NOTE: Enterprise customers may have a business need to either delay or force updates to any node with access to a private network.
* UC-1: not required
* UC-2: not required
* UC-3: not required
* UC-4: not required
* UC-5: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-6: not required
* UC-7: not required
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-7: required
### 5.5.5 REQ-SU-05 (MI-SUVP) Secure update via product
@@ -561,7 +561,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: not required
* UC-6: required
* UC-7: required
### 5.6.6 REQ-AAC-06 (MI-AUTH-5) Forced revocation of authorization of endpoints
@@ -582,7 +582,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: not required
* UC-6: required
* UC-7: required
### 5.6.7 REQ-AAC-07 (MI-AUTH-6) Brute force protection
@@ -624,7 +624,7 @@ A node shall only allow connections from authorized endpoints.
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: not required
* UC-6: required
* UC-7: required
### 5.6.9 REQ-AAC-09 (MI-TRAF-5) Fine-grain access control
@@ -757,7 +757,7 @@ The VPN traffic shall be encrypted using session keys generated and held only by
#### 5.7.6.1 Requirement
1.**REQ-CON-06 (MI-DNSL-1)-1** The VPN client shall prominently inform the user of the visibility of plaintext DNS queries outside the tunnel under the current configuration and the consequences in simple plain language, focusing on the potential risk and impact to the user of such handling and, where applicable, potential steps to resolve this risk, and
1.**REQ-CON-06 (MI-DNSL-1)-1** The VPN client shall prominently inform the user of the visibility of DNS queries outside the tunnel under the current configuration and the consequences in simple plain language, focusing on the potential risk and impact to the user of such handling and, where applicable, potential steps to resolve this risk, and
2.**REQ-CON-06 (MI-DNSL-1)-2** the product shall require the user to actively confirm having read the information before being able to use the VPN connection.
#### 5.7.6.2 Applicability
@@ -940,6 +940,22 @@ Depending on the data type and operational environment, the product shall protec
* UC-6: required
* UC-7: required
### 5.7.16 REQ-CON-16 Inform user of limits of privacy protection
#### 5.7.16.1 Requirement
The product shall inform the user of the limitations of any privacy protection.
@@ -958,6 +974,7 @@ Depending on the data type and operational environment, the product shall protec
| REQ-CON-13 (MI-IPV6-2) | x | x | x | x | x | x | x |
| REQ-CON-14 (MI-CRYPT-1) | x | x | x | x | x | x | x |
| REQ-CON-15 (MI-CDST) | x | x | x | x | x | x | x |
| REQ-CON-16 | | x | x | | | | x |
## 5.8 Integrity protection
@@ -1075,7 +1092,7 @@ The product shall not collect data unnecessary for the operation of the product.
#### 5.9.2.1 Requirement
The product shall not collect Personal Data unless the collection is necessary for an intended purpose of the product, or the user or administrator has explicitly authorized it.
The product shall not collect Personal Data unless the collection is necessary for an intended purpose of the product, or the user has explicitly authorized it.
#### 5.9.2.2 Applicability
@@ -1148,7 +1165,7 @@ The VPN shall not store any Personal Data of the user on the VPN server, gateway