Verified Commit 664b74a2 authored by Aki Braun's avatar Aki Braun
Browse files

USERS!

- Rework users from @rotoloj
- Remove numbering within clause 4
- More use case polish
parent 318a2dc8
Loading
Loading
Loading
Loading
+68 −80
Original line number Diff line number Diff line
@@ -304,9 +304,7 @@ For the purposes of the present document, abbreviations given in [TK document fr

# 4 Product context

## 4.1 Null

## 4.2 Out of scope use/environments
## 4.X Out of scope use/environments

The types of product with digital elements listed in the section do not fall within the scope of the the Regulation (EU) 2024/2847 (Cyber Resilience Act), and are not covered by this standard:

@@ -325,17 +323,17 @@ The following types of products have reduced or varied requirements under Regula
10. Testing and unfinished versions as defined in recital 37; Article 4, 2-3 <a href="#_ref_i.1">[i.1]</a>;
11. Products Placed on the Market Prior to December 11, 2027 as defined in CRA article 69 <a href="#_ref_i.1">[i.1]</a>.

## 4.3 Product overview and architecture
## 4.X Product overview and architecture

> Explain the overall architecture and relationship among the parts of the products. Use diagrams if that is helpful.

### 4.3.1 Product overview
### 4.X.1 Product overview

As a holistic product, a Virtual Private Network includes, at minimum, VPN software capable of establishing a secure encrypted tunnel on two or more devices. VPN products also provide management capabilities to network administrators: user and group management, access control, logging and monitoring.

![A diagram illustrating an offsite device using a VPN client to encrypt traffic and send it through a public network, to a VPN server which decrypts the traffic.](./media/VPN%20diagrams.svg)

### 4.2.2 Architecture
### 4.X.2 Architecture

Virtual Private Networks can differ in topologies used to transmit data and distribute configuration. Two common distinct topologies are hub-and-spoke networks and mesh networks; in practice, networks can use more complex mixed topologies that fall somewhere in between the two extremes.

@@ -347,17 +345,17 @@ In a mesh network, clients and gateways establish direct tunnels between each ot

![A diagram illustrating a mesh network.](./media/mesh.drawio.png)

### 4.2.3 VPN client
### 4.X.3 VPN client

VPN client is a piece of software responsible for connecting a single end-point to a private network. It typically uses authentication credentials provided by the end-user to establish secure tunnel(s) to other participant(s) of the network: a VPN server, or other VPN clients and gateways (in case of a mesh network).

After establishing a tunnel, the VPN client changes configuration of the operating system to facilitate connections to the private network - this can include changes to DNS configuration, firewall rules, routing table, etc. This configuration is tailored to the end-user, and is based on a combination of local user preferences and policies configured centrally by the network administrator.

### 4.2.4 VPN server, VPN gateway, VPN concentrator
### 4.X.4 VPN server, VPN gateway, VPN concentrator

A VPN server is responsible for maintaining tunnels with VPN clients, acting as a gateway to the private network for those clients.

### 4.2.5 Management server
### 4.X.5 Management server

Management server provides a way for network administrators to control configuration and membership of their network. This can include:

@@ -369,7 +367,7 @@ Management server typically maintains configuration of the whole network, and pr

In VPNs using a hub-and-spoke topology, management server is often implemented as part of the VPN server.

## 4.4 Use cases
## 4.X Use cases

> When you have many use cases, group them into 3 - 5 levels of risk. These will probably be your security levels.

@@ -389,39 +387,26 @@ This list of use cases is an informative resource to the manufacturer to simplif
  * hybrid setup of on-premises and cloud

* **UC-3** Large enterprise, university, non-classified government entities
  * distinct network and IT teams
  * well-defined network and IT teams
  * experienced IT professionals managing configuration
  * connecting distributed workforce and multiple locations with distinct private networks (including data centres and cloud)
  * expects fine-grained control of configuration and management

* **UC-4** Hospitals, financial institutions, certain newspapers and broadcasters
  * likely targets of organised bad actors
  * establish tunnel to evade surveillance
  * increased security needs

## 4.5 Risk factors

### 4.5.1 List of risk factors

XXX client risks

BYOD policies

XXX mesh untrusted device risks

XXX management risks

XXX access risks

XXX target risks
* **UC-4** Hospitals, financial institutions, high-impact institutions
  * well-defined network and IT teams
  * experienced IT professionals managing configuration
  * distributed workforce may not have advanced security skills congruent with IT needs
  * expects fine-grained control of configuration and management

====
* **UC-5** High-risk targets, certain newspapers and broadcasters
  * likely targets of organised bad actors
  * utilise secure tunnels to evade surveillance
  * users likely have above-average security awareness
  * require more hardened systems

USERS
## 4.X Risk factors

XXX end users
XXX administrators
XXX operations
### 4.X.1 List of risk factors

The risk factors identified by the risk assessment in Annex C are grouped into risk categories and assigned unique identifiers below.

@@ -453,19 +438,19 @@ The risk factors identified by the risk assessment in Annex C are grouped into r
  * **PHY-L-N**
  * **PHY-L-N**

### 4.5.1 Mapping of use cases to risk factors and security levels
### 4.X.1 Mapping of use cases to risk factors and security levels

| Use case | USR | CFG | AUT | ADM | Sec Lev |
|----------|-----|-----|-----|-----|---------|
| UC-TK-1  | L-0 | L-0 | L-1 | L-0 | SC-TK-1 |

## 4.6 Security levels
## 4.X Security levels

> List the security levels and the use cases that correspond to them.

Security levels are an informative resource to the manufacturer. Each security level is associated with a collection of levels of risk factors. Security levels will be mapped to the security requirements necessary to mitigate them in a future draft.

### 4.6.2 Mapping of security level to risk factors
### 4.X.2 Mapping of security level to risk factors

Each security level will consist of the security requirements necessary to mitigate the threats related to the associated levels of risk factors.

@@ -475,7 +460,7 @@ Each security level will consist of the security requirements necessary to mitig
|----------------|---------------|---------------|---------------|
| TK-L1          |               |               |               |

## 4.7 Essential functions
## 4.X Essential functions

> List the essential functions of the product, including:
>
@@ -523,7 +508,7 @@ During reasonably foreseeable use, nodes may:
* Leave the restricted network
* Revoke the access of a node to the restricted use network

## 4.8 Operational Environment
## 4.X Operational Environment

> Describe the expected operating environment given the exclusions in Section 4.2. This includes:
>
@@ -533,7 +518,7 @@ During reasonably foreseeable use, nodes may:
> - Supporting/associated software or services
> - Other relevant context

### 4.7.1 Physical environment
### 4.X.1 Physical environment

The technical requirements of the present document apply under the environmental profile for operation of the equipment, which shall be in accordance with its intended use. The equipment shall comply with all the technical requirements of the present document at all times when operating within the boundary limits of the operational environmental profile defined by its intended use.

@@ -543,7 +528,7 @@ The physical hardware the VPN product is using may be:
* In a private home
* In a public area

### 4.7.2 Digital environment
### 4.X.2 Digital environment

VPNs can be expected to operate in a network environment alongside other Important PwDEs such as Identity Access Management, Network Interfaces, Routers, Firewalls, and SIEM systems. Manufacturers shall harden VPN attack surfaces against potential attack vectors from compromised PwDEs, but in particular those considered Important and Critical. See clause TK for further information about the relationship between VPNs and related software.

@@ -574,78 +559,80 @@ VPN products often include or are use in concert with:
* Distributed log collection and monitoring
* Firewalls

## 4.9 Users
## 4.X Users

### 4.8.1 User Types and Descriptions

#### 4.8.1.1 Overview
### 4.X.1 Overview

This section describes the different classes of users for VPN products, differentiating them by their security expertise, goals, and the threats they are most likely to face.

#### 4.8.1.2 University student
### 4.X.2 Types of users

#### 4.X.2.1 End-point users

* **USR-1**: Small business worker

  This user type is not expected to have high security expertise, and uses VPN for added security when accessing SaaS products associated with their work. Their expectation is for a simple, pre-configured product that requires minimal user intervention.

* **USR-2** University student

  This user type is not expected to have high security expertise and utilizes VPN products for accessing university resources while away from campus. Their expectation is for a simple, pre-configured product that requires minimal user intervention.

**USER-1**
: This user type is not expected to have high security expertise and utilizes VPN products for accessing university resources while away from campus. Their expectation is for a simple, pre-configured product that requires minimal user intervention.
* **USR-3**: Distributed Workers

#### 4.8.1.3 Enterprise IT / Administrators
  This user type consists of employees or contractors of an organization who perform job duties from a remote location. They are end-users of an enterprise VPN and require a reliable and secure connection to the corporate network to access resources and handle sensitive information. The security posture of their VPN client is managed and enforced by the Enterprise IT team.

**USER-2**
: This user type is composed of professionals with high technical and security expertise. The responsibilities of this group include the procurement, deployment, and management of VPN products within a corporate or institutional environment. This user type is responsible for establishing and maintaining secure connectivity, access controls, and security policies to protect corporate assets, intellectual property, and user data.
#### 4.X.2.2 VPN management users

#### 4.8.1.4 Distributed Workers
_Note that most manager users are also likely end-point users, with moderate to advanced cybersecurity skills._

**USER-3**
: This user type consists of employees or contractors of an organization who perform job duties from a remote location. They are end-users of an enterprise VPN and require a reliable and secure connection to the corporate network to access resources and handle sensitive information. The security posture of their VPN client is managed and enforced by the Enterprise IT team.
* **MGR-1**: Enterprise IT / Administrators

#### 4.8.1.5 Software Operations & Development
  This user type is composed of professionals with high technical and security expertise. The responsibilities of this group include the procurement, deployment, and management of VPN products within a corporate or institutional environment. This user type is responsible for establishing and maintaining secure connectivity, access controls, and security policies to protect corporate assets, intellectual property, and user data.

**USER-4**
: This user type comprises highly technical individuals who manage secure connections between data centers, cloud environments, or other technical infrastructure. The primary goal of this group is to ensure secure and high-performance data transfer for critical operational workflows. This user type is responsible for the implementation and maintenance of VPNs utilized for managing sensitive data and intellectual property.
* **MGR-2**: Software Operations & Development

#### 4.8.1.6 High-Risk & Advanced Users
  This user type comprises highly technical individuals who manage secure connections between data centers, cloud environments, or other technical infrastructure. The primary goal of this group is to ensure secure and high-performance data transfer for critical operational workflows. This user type is responsible for the implementation and maintenance of VPNs utilized for managing sensitive data and intellectual property.

**USER-5**
: This user type is associated with individuals or organizations that are potential targets of sophisticated and high-resource adversaries. These users require a VPN product that provides the highest level of security and anonymity, and they are assumed to have advanced security knowledge to configure and manage the product's features.
* **MGR-3**: High-Risk & Advanced Users

## 4.10 Distribution of security functions
  This user type is associated with individuals or organizations that are potential targets of sophisticated and high-resource adversaries. These users require a VPN product that provides the highest level of security and anonymity, and they are assumed to have advanced security knowledge to configure and manage the product's features.

### 4.8.2 User Needs by Security Level (Pending Security Levels Definition)
### 4.X.3 User security needs

#### 4.8.2.1 Overview
#### 4.X.3.1 Overview

The different user types have varying needs that correspond directly to the security levels defined in this standard. A manufacturer should take these into account to ensure the product's security is proportionate to its intended use.

#### 4.8.2.2 Base Security
#### 4.X.3.2 Basic security

**User**: USER-1 Consumers
**User**: USR-1 Small-business worker, USR-2 university student

**Needs**: Easy to install and use, "secure by default" configuration, minimal user intervention, and reliable privacy protection against low-sophistication threats on untrusted public networks. Logging should be minimal, if it exists at all.

#### 4.8.2.3 General Security
#### 4.X.3.3 General Security

**Users**: USER-2 Enterprise IT and Distributed Workers
**Users**: MGR-1 Enterprise IT and USR-3 Distributed Workers

**Needs**: A centrally managed and configurable solution. Enterprise IT needs robust authentication and access control, logging of configuration changes, and integration with other security tools like firewalls and logging services. Distributed Workers need a secure and reliable client that enforces corporate policies without requiring a high degree of technical knowledge from the end-user.

#### 4.8.2.4 Critical Security
#### 4.X.3.4 Critical Security

**Users**: USER-3, USER-4 Software Operations & Development and High-Risk & Advanced Users
**Users**: MGR-3 Software Operations & Development and MGR-4 High-Risk & Advanced Users

**Needs**: This level requires the highest standards of security. Users need a VPN solution that provides advanced cryptographic protection, resistance to sophisticated attacks, and auditable logging of all relevant activities. For technical operations, it must support high-performance, resilient connections between data centers. For high-risk individuals, it must offer strong anonymity and protection against state-level adversaries.

### 4.8.3 User Needs and Associated Security Levels (TBD)
#### 4.X.3.5 User Needs and Associated Security Levels (TBD)

This table maps the user types to the corresponding use cases and the security levels required to meet their needs. This mapping serves as a basis for defining conditional or advanced requirements.

| User Type    | Associated Use Case(s)                           | Security Level    |
|-----------------------------------|--------------------------------------------------|-------------------|
| Consumers                         | Consumer VPN service                             | Base Security     |
| Enterprise IT / Administrators    | VPN software for enterprise workforce deployment | General Security  |
| Distributed Workers               | VPN software for enterprise workforce deployment | General Security  |
| Software Operations & Development | VPN software connecting data centres             | Critical Security |
| High-Risk & Advanced Users        | Commercial VPN service for high-risk targets     | Critical Security |
|--------------|--------------------------------------------------|-------------------|
| USR-1, USR-2 | SaaS VPN service                                 | Base Security     |
| USR-3, MGR-1 | VPN software for enterprise workforce deployment | General Security  |
| MGR-3        | VPN software connecting data centres             | Critical Security |
| MGR-4        | Commercial VPN service for high-risk targets     | Critical Security |

## 4.10 Risk distribution among components
## 4.X Risk distribution among components

> Risk can be transferred between components, for example a network interface can document that secure update of its firmware must be handled by an external program, such as an operating system. In turn, the operating system can offer the security functionality of secure updates to other components in a system.

@@ -694,6 +681,7 @@ Enterprise VPN software is a challenging and resource-heavy deployment process,

- Activity logs
- Configuration data
- CA information, certificates & keys (public, private, PSK)

### C.1.2 Product functions