+83
−41
+119
−144
File changed.
Preview size limit exceeded, changes collapsed.
+77
−67
+212
−1669
File changed.
Preview size limit exceeded, changes collapsed.
Loading
DNS routing is not a primary use-case for mesh. Mesh networks focus on connecting endpoints together, but do not nessecary tunnel internet traffic, but rather create a vLAN updated table updated table Apply logging to remote serever requirements to enterprise with distinctive requirement for logging to RDPS or not Removed that personal data can not be logged Updated numbering Added and updated assessment criteria More cleary differentiate as-yet-unnumbered requirements Hard to review things that are numbered wrong, sorry about that. That means list items too And you🤦🏻♀️ sorry, for the noise. the caffiene hasn't kicked in yet Updates based on discussion with legal Revert change Apply 1 suggestion(s) to 1 file(s) Co-authored-by:Aki Braun <a@expertzebra.com> Added note on logging free text inputs Specified injection attack removed unnessecary 'internal' Removed internal from 5. Spelling fixes Spelling fix Addressed comments on MR Apply 1 suggestion(s) to 1 file(s) Co-authored-by:
Aki Braun <a@expertzebra.com> ESR 14 Language tweaks for consistency and clarity Edit Annex R for application to EN 304 620 Move no data persistence to Data Minimisation clause Clearer langauge for DNS query "monitoring" Annex B.1: Expand with explanation, more assets, impact/value closes #342 Clause 5.1: explain relationship of assets, risk factors, requirements closes #344 Annex C.2.8 predictable -> reliable close #346 Annex C.2.8: Make DNC-1 and DNC-2 exclusive closes #347 Annex C.2.10: explain rationale for increased risk closes #351 Annex C.2.1: Add link from risk factors to risk factors level definition closes #356 Annex C.2.6: Improve rationale for admin risk factor closes #366 Annex C.2.7: Improve rationale for RDPS factor closes #368 Annex C.2.10: Add guidance to COM risk factor closes #348 Remove rogue merge artifact from Clause 5.13.4 Clause 5/6 Update requirements for risk transfer to operational environment Explcitly exempt enterprise VPNs from requirements using transfer of risk to the operational environment via the "REQ-1 or REQ-2" construct. Limit this exemption to mitigations for threats that the operational environment can mitigate, like denial of service attacks but not credential cloning. Remove accidental inclusion of "no traffic routing through node by default" requirement for UC-6. Remove documentation of risk transfer for denial of service from the remaining use cases. closes #483 Annex B (was C): remove rogue "must" Annex C.3: Explain role of assumptions and remove identifiers Clause 5.5: Remove redundant and not allowed secure update documentation reqs We can't require documentation and these are redundant with update via operational environment (coming soon as an expansion of the administrator options). Remove 5.10.6 REQ-AP-06 (MI-DOST-3) as redundant to Annex R
File changed.
Preview size limit exceeded, changes collapsed.
File changed.
Preview size limit exceeded, changes collapsed.