@@ -304,9 +304,7 @@ For the purposes of the present document, abbreviations given in [TK document fr
# 4 Product context
## 4.1 Null
## 4.2 Out of scope use/environments
## 4.X Out of scope use/environments
The types of product with digital elements listed in the section do not fall within the scope of the the Regulation (EU) 2024/2847 (Cyber Resilience Act), and are not covered by this standard:
@@ -325,17 +323,17 @@ The following types of products have reduced or varied requirements under Regula
10. Testing and unfinished versions as defined in recital 37; Article 4, 2-3 <ahref="#_ref_i.1">[i.1]</a>;
11. Products Placed on the Market Prior to December 11, 2027 as defined in CRA article 69 <ahref="#_ref_i.1">[i.1]</a>.
## 4.3 Product overview and architecture
## 4.X Product overview and architecture
> Explain the overall architecture and relationship among the parts of the products. Use diagrams if that is helpful.
### 4.3.1 Product overview
### 4.X.1 Product overview
As a holistic product, a Virtual Private Network includes, at minimum, VPN software capable of establishing a secure encrypted tunnel on two or more devices. VPN products also provide management capabilities to network administrators: user and group management, access control, logging and monitoring.

### 4.2.2 Architecture
### 4.X.2 Architecture
Virtual Private Networks can differ in topologies used to transmit data and distribute configuration. Two common distinct topologies are hub-and-spoke networks and mesh networks; in practice, networks can use more complex mixed topologies that fall somewhere in between the two extremes.
@@ -347,17 +345,17 @@ In a mesh network, clients and gateways establish direct tunnels between each ot

### 4.2.3 VPN client
### 4.X.3 VPN client
VPN client is a piece of software responsible for connecting a single end-point to a private network. It typically uses authentication credentials provided by the end-user to establish secure tunnel(s) to other participant(s) of the network: a VPN server, or other VPN clients and gateways (in case of a mesh network).
After establishing a tunnel, the VPN client changes configuration of the operating system to facilitate connections to the private network - this can include changes to DNS configuration, firewall rules, routing table, etc. This configuration is tailored to the end-user, and is based on a combination of local user preferences and policies configured centrally by the network administrator.
* experienced IT professionals managing configuration
* distributed workforce may not have advanced security skills congruent with IT needs
* expects fine-grained control of configuration and management
====
***UC-5** High-risk targets, certain newspapers and broadcasters
* likely targets of organised bad actors
* utilise secure tunnels to evade surveillance
* users likely have above-average security awareness
* require more hardened systems
USERS
## 4.X Risk factors
XXX end users
XXX administrators
XXX operations
### 4.X.1 List of risk factors
The risk factors identified by the risk assessment in Annex C are grouped into risk categories and assigned unique identifiers below.
@@ -453,19 +438,19 @@ The risk factors identified by the risk assessment in Annex C are grouped into r
***PHY-L-N**
***PHY-L-N**
### 4.5.1 Mapping of use cases to risk factors and security levels
### 4.X.1 Mapping of use cases to risk factors and security levels
| Use case | USR | CFG | AUT | ADM | Sec Lev |
|----------|-----|-----|-----|-----|---------|
| UC-TK-1 | L-0 | L-0 | L-1 | L-0 | SC-TK-1 |
## 4.6 Security levels
## 4.X Security levels
> List the security levels and the use cases that correspond to them.
Security levels are an informative resource to the manufacturer. Each security level is associated with a collection of levels of risk factors. Security levels will be mapped to the security requirements necessary to mitigate them in a future draft.
### 4.6.2 Mapping of security level to risk factors
### 4.X.2 Mapping of security level to risk factors
Each security level will consist of the security requirements necessary to mitigate the threats related to the associated levels of risk factors.
@@ -475,7 +460,7 @@ Each security level will consist of the security requirements necessary to mitig
> List the essential functions of the product, including:
>
@@ -523,7 +508,7 @@ During reasonably foreseeable use, nodes may:
* Leave the restricted network
* Revoke the access of a node to the restricted use network
## 4.8 Operational Environment
## 4.X Operational Environment
> Describe the expected operating environment given the exclusions in Section 4.2. This includes:
>
@@ -533,7 +518,7 @@ During reasonably foreseeable use, nodes may:
> - Supporting/associated software or services
> - Other relevant context
### 4.7.1 Physical environment
### 4.X.1 Physical environment
The technical requirements of the present document apply under the environmental profile for operation of the equipment, which shall be in accordance with its intended use. The equipment shall comply with all the technical requirements of the present document at all times when operating within the boundary limits of the operational environmental profile defined by its intended use.
@@ -543,7 +528,7 @@ The physical hardware the VPN product is using may be:
* In a private home
* In a public area
### 4.7.2 Digital environment
### 4.X.2 Digital environment
VPNs can be expected to operate in a network environment alongside other Important PwDEs such as Identity Access Management, Network Interfaces, Routers, Firewalls, and SIEM systems. Manufacturers shall harden VPN attack surfaces against potential attack vectors from compromised PwDEs, but in particular those considered Important and Critical. See clause TK for further information about the relationship between VPNs and related software.
@@ -574,78 +559,80 @@ VPN products often include or are use in concert with:
* Distributed log collection and monitoring
* Firewalls
## 4.9 Users
## 4.X Users
### 4.8.1 User Types and Descriptions
#### 4.8.1.1 Overview
### 4.X.1 Overview
This section describes the different classes of users for VPN products, differentiating them by their security expertise, goals, and the threats they are most likely to face.
#### 4.8.1.2 University student
### 4.X.2 Types of users
#### 4.X.2.1 End-point users
***USR-1**: Small business worker
This user type is not expected to have high security expertise, and uses VPN for added security when accessing SaaS products associated with their work. Their expectation is for a simple, pre-configured product that requires minimal user intervention.
***USR-2** University student
This user type is not expected to have high security expertise and utilizes VPN products for accessing university resources while away from campus. Their expectation is for a simple, pre-configured product that requires minimal user intervention.
**USER-1**
: This user type is not expected to have high security expertise and utilizes VPN products for accessing university resources while away from campus. Their expectation is for a simple, pre-configured product that requires minimal user intervention.
***USR-3**: Distributed Workers
#### 4.8.1.3 Enterprise IT / Administrators
This user type consists of employees or contractors of an organization who perform job duties from a remote location. They are end-users of an enterprise VPN and require a reliable and secure connection to the corporate network to access resources and handle sensitive information. The security posture of their VPN client is managed and enforced by the Enterprise IT team.
**USER-2**
: This user type is composed of professionals with high technical and security expertise. The responsibilities of this group include the procurement, deployment, and management of VPN products within a corporate or institutional environment. This user type is responsible for establishing and maintaining secure connectivity, access controls, and security policies to protect corporate assets, intellectual property, and user data.
#### 4.X.2.2 VPN management users
#### 4.8.1.4 Distributed Workers
_Note that most manager users are also likely end-point users, with moderate to advanced cybersecurity skills._
**USER-3**
: This user type consists of employees or contractors of an organization who perform job duties from a remote location. They are end-users of an enterprise VPN and require a reliable and secure connection to the corporate network to access resources and handle sensitive information. The security posture of their VPN client is managed and enforced by the Enterprise IT team.
***MGR-1**: Enterprise IT / Administrators
#### 4.8.1.5 Software Operations & Development
This user type is composed of professionals with high technical and security expertise. The responsibilities of this group include the procurement, deployment, and management of VPN products within a corporate or institutional environment. This user type is responsible for establishing and maintaining secure connectivity, access controls, and security policies to protect corporate assets, intellectual property, and user data.
**USER-4**
: This user type comprises highly technical individuals who manage secure connections between data centers, cloud environments, or other technical infrastructure. The primary goal of this group is to ensure secure and high-performance data transfer for critical operational workflows. This user type is responsible for the implementation and maintenance of VPNs utilized for managing sensitive data and intellectual property.
***MGR-2**: Software Operations & Development
#### 4.8.1.6 High-Risk & Advanced Users
This user type comprises highly technical individuals who manage secure connections between data centers, cloud environments, or other technical infrastructure. The primary goal of this group is to ensure secure and high-performance data transfer for critical operational workflows. This user type is responsible for the implementation and maintenance of VPNs utilized for managing sensitive data and intellectual property.
**USER-5**
: This user type is associated with individuals or organizations that are potential targets of sophisticated and high-resource adversaries. These users require a VPN product that provides the highest level of security and anonymity, and they are assumed to have advanced security knowledge to configure and manage the product's features.
***MGR-3**: High-Risk & Advanced Users
## 4.10 Distribution of security functions
This user type is associated with individuals or organizations that are potential targets of sophisticated and high-resource adversaries. These users require a VPN product that provides the highest level of security and anonymity, and they are assumed to have advanced security knowledge to configure and manage the product's features.
### 4.8.2 User Needs by Security Level (Pending Security Levels Definition)
### 4.X.3 User security needs
#### 4.8.2.1 Overview
#### 4.X.3.1 Overview
The different user types have varying needs that correspond directly to the security levels defined in this standard. A manufacturer should take these into account to ensure the product's security is proportionate to its intended use.
#### 4.8.2.2 Base Security
#### 4.X.3.2 Basic security
**User**: USER-1 Consumers
**User**: USR-1 Small-business worker, USR-2 university student
**Needs**: Easy to install and use, "secure by default" configuration, minimal user intervention, and reliable privacy protection against low-sophistication threats on untrusted public networks. Logging should be minimal, if it exists at all.
#### 4.8.2.3 General Security
#### 4.X.3.3 General Security
**Users**: USER-2 Enterprise IT and Distributed Workers
**Users**: MGR-1 Enterprise IT and USR-3 Distributed Workers
**Needs**: A centrally managed and configurable solution. Enterprise IT needs robust authentication and access control, logging of configuration changes, and integration with other security tools like firewalls and logging services. Distributed Workers need a secure and reliable client that enforces corporate policies without requiring a high degree of technical knowledge from the end-user.
#### 4.8.2.4 Critical Security
#### 4.X.3.4 Critical Security
**Users**: USER-3, USER-4 Software Operations & Development and High-Risk & Advanced Users
**Users**: MGR-3 Software Operations & Development and MGR-4 High-Risk & Advanced Users
**Needs**: This level requires the highest standards of security. Users need a VPN solution that provides advanced cryptographic protection, resistance to sophisticated attacks, and auditable logging of all relevant activities. For technical operations, it must support high-performance, resilient connections between data centers. For high-risk individuals, it must offer strong anonymity and protection against state-level adversaries.
### 4.8.3 User Needs and Associated Security Levels (TBD)
#### 4.X.3.5 User Needs and Associated Security Levels (TBD)
This table maps the user types to the corresponding use cases and the security levels required to meet their needs. This mapping serves as a basis for defining conditional or advanced requirements.
| User Type | Associated Use Case(s) | Security Level |
| MGR-4 | Commercial VPN service for high-risk targets | Critical Security |
## 4.10 Risk distribution among components
## 4.X Risk distribution among components
> Risk can be transferred between components, for example a network interface can document that secure update of its firmware must be handled by an external program, such as an operating system. In turn, the operating system can offer the security functionality of secure updates to other components in a system.
@@ -694,6 +681,7 @@ Enterprise VPN software is a challenging and resource-heavy deployment process,
- Activity logs
- Configuration data
- CA information, certificates & keys (public, private, PSK)