Verified Commit 75e0bd5d authored by Aki Braun's avatar Aki Braun
Browse files

Editorial: Caption and number all tables

Closes #484
parent 23305215
Loading
Loading
Loading
Loading
+10 −6
Original line number Diff line number Diff line
@@ -232,6 +232,8 @@ There are no symbols requiring definition used in the present document.

For the purposes of the present document, the following abbreviations apply:

**Table 3.3: Abbreviations**

| Abbreviation |                                           |
|--------------|-------------------------------------------|
| CRA          | Cyber Resilience Act                      |
@@ -610,9 +612,7 @@ The purpose of cybersecurity is to protect the product assets, which include pro

### B.1.1 Data assets

<span id="tab_BDA"></span>

Table { seq tab }: VPN product data assets
**Table B.1.1: VPN product data assets**

| Asset                                 | Compromise impacts                    | Value  |
|---------------------------------------|---------------------------------------|--------|
@@ -630,9 +630,7 @@ Table { seq tab }: VPN product data assets

What follows is a basic overview of VPN functions. See [clause 4.2](#product-architecture) for a detailed overview of the functions of a VPN product.

<span id="tab_BPF"></span>

Table { seq tab }: VPN product functions
**Table B.1.2: VPN product functions**

| Asset                                          | Compromise impacts            | Value  |
|------------------------------------------------|-------------------------------|--------|
@@ -644,6 +642,8 @@ Table { seq tab }: VPN product functions

### B.1.3 Digital assets

**Table B.1.3: VPN digital assets**

| Asset                     | Compromise impacts                           | Value        |
|---------------------------|----------------------------------------------|--------------|
| VPN server applications   | Everything                                   | Astronomical |
@@ -651,6 +651,8 @@ Table { seq tab }: VPN product functions

### B.1.4 Human-associated assets

**Table B.1.4: VPN human-associated assets**

| Asset          | Compromise impacts           | Value  |
|----------------|------------------------------|--------|
| Credentials    | Authorization/access control | High   |
@@ -1996,6 +1998,8 @@ For each risk untreated by the product itself in any applicable use case, a corr

## B.9 All use cases and requirements

**Table B.9: Requirement to use case mapping**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-SSD-01 |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |
+30 −2
Original line number Diff line number Diff line
@@ -93,6 +93,8 @@ This requirement does not apply to UC-6 because by definition that use case does

### 5.2.5 Mapping of requirements to use cases

**Table 5.2.5: Appropriate level of cybersecurity requirements mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-SSD-01 |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |  x¹  |
@@ -138,6 +140,8 @@ From a practical standpoint, a known exploitable vulnerability is a flaw that ha

### 5.3.3 Mapping of requirements to use cases

**Table 5.3.3: Known exploitable vulnerabilities mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-KEV-01 |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
@@ -170,6 +174,8 @@ This requirement applies to the subset of products in the indicated use cases wh

### 5.4.3 Mapping of requirements to use cases

**Table 5.4.3: Secure by default mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-SBD-01 |  x   |  x   |  x   |      |  x   |  x   |      |
@@ -463,6 +469,8 @@ The product shall reject Repository Metadata if its version number is equal to o

### 5.5.16 Mapping of requirements to use cases

**Table 5.5.16: Security updates mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|    REQ-SU-01 |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
@@ -644,6 +652,8 @@ This requirement applies to the subset of products within the indicated use case

### 5.6.10 Mapping of requirements to use cases

**Table 5.6.10: Authentication and access control mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-AAC-01 |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
@@ -954,6 +964,8 @@ The product shall inform the user of the limitations of any privacy protection.

### 5.7.17 Mapping of requirements to use cases

**Table 5.7.17: Confidentiality mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-CON-01 |      |  x   |  x   |  x   |  x   |  x   |  x   |
@@ -1065,6 +1077,8 @@ The product shall provide a method to implement data validity checks on all inco

### 5.8.7 Mapping of requirements to use cases

**Table 5.8.7: Integrity protection mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-INT-01 |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
@@ -1167,6 +1181,8 @@ The VPN shall not store any Personal Data of the user on the VPN server, gateway

### 5.9.7 Mapping of requirements to use cases

**Table 5.9.6: Data minimisation mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|    REQ-DM-01 |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
@@ -1253,6 +1269,8 @@ The product shall rate limit traffic from unauthenticated endpoints to nodes.

### 5.10.6 Mapping of requirements to use cases

**Table 5.10.6: Availability protection mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|    REQ-AP-01 |  x⁸  |  x⁸  |  x⁹  |  x⁸  |  x⁹  |  x⁹  |  x⁸  |
@@ -1307,6 +1325,8 @@ Denial of service attacks over the network often use traffic reflection or ampli

### 5.11.4 Mapping of requirements to use cases

**Table 5.11.4: Non-interference mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|    REQ-IM-01 |      |  x   |  x   |      |      |      |      |
@@ -1342,6 +1362,8 @@ The VPN product should be able to operate without a wide set of permissions—eg

### 5.12.3 Mapping of requirements to use cases

**Table 5.12.3: Attack surface minimization mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-MAS-01 |      |  x   |  x   |  x   |  x   |  x   |  x   |
@@ -1404,6 +1426,8 @@ The VPN client shall not require routing of traffic from sources/destinations ot

### 5.13.5 Mapping of requirements to use cases

**Table 5.13.5: Exploit mitigation mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-EMM-01 |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
@@ -1517,6 +1541,8 @@ Logging output is expected to take care to not accidentally include a secret as

### 5.14.6 Mapping of requirements to use cases

**Table 5.14.6: Monitoring mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-LOG-01 |  x†  |  x†  |  x†  |  x†  |  x†  |  x†  |  x†  |
@@ -1614,6 +1640,8 @@ This requirement applies to the subset of products within the indicated use case

### 5.15.6 Mapping of requirements to use cases

**Table 5.15.6: Factory reset mapping to use cases**

| Requirements | UC-1 | UC-2 | UC-3 | UC-4 | UC-5 | UC-6 | UC-7 |
|-------------:|:----:|:----:|:----:|:----:|:----:|:----:|:----:|
|   REQ-DRT-01 |  x   |  x   |  x   |  x   |  x   |  x   |  x   |
+3 −3
Original line number Diff line number Diff line
@@ -179,9 +179,9 @@ Where the product’s default configuration uses ACM-extended cryptographic mech

### K.3.2 List of ACM-extended cryptographic mechanisms

Table K.1 lists the ACM-extended cryptographic mechanisms specified by the present document.
Table K.3.2 lists the ACM-extended cryptographic mechanisms specified by the present document.

**Table K.1: ACM-extended cryptographic mechanisms**
**Table K.3.2: ACM-extended cryptographic mechanisms**

| ACM-extended cryptographic mechanism | Type of cryptographic mechanism | Characteristics / parameters                                                                                                                                                                                                 | Related product function(s) / use case(s), where applicable | Cryptographic properties                           | Specification / reference                                                                                         | Conditions or limitations, where applicable |
|:-------------------------------------|:--------------------------------|:-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------------------|:---------------------------------------------------|:------------------------------------------------------------------------------------------------------------------|:--------------------------------------------|
@@ -201,7 +201,7 @@ Table K.1 lists the ACM-extended cryptographic mechanisms specified by the prese
| Blake3                               | Algorithm                       |                                                                                                                                                                                                                              | Key derivation, Generic hashing, MAC                        | Authentication, integrity                          | BLAKE3 [\[12\]](#_ref_12), [C2SP](https://github.com/C2SP/C2SP)                                                   |                                             |
| UMAC                                 | Algorithm                       | 128 bit                                                                                                                                                                                                                      | MAC                                                         | Authentication, Integrity                          | RFC 4418 [\[11\]](#_ref_11)                                                                                       |                                             |

> NOTE 1: The combination of the mechanism mentioned in Table K.1: ACM-extended cryptographic mechanisms together with the mechanisms in ACM that is appropriate for the cryptographic use-case to form a cryptographic protocol are allowed. For example ChaCha20-Poly1305, HMAC-blake2s or X25519ML-KEM768.
> NOTE 1: The combination of the mechanism mentioned in Table K.3.2: ACM-extended cryptographic mechanisms together with the mechanisms in ACM that is appropriate for the cryptographic use-case to form a cryptographic protocol are allowed. For example ChaCha20-Poly1305, HMAC-blake2s or X25519ML-KEM768.

> NOTE 2: The use-case defined in K.3.2 marked in “Related product function(s) / use case(s), where applicable” is a non-exhaustive list and listed algorithm can be used for other appropriate use-cases as well.

+5 −5
Original line number Diff line number Diff line
@@ -56,7 +56,7 @@ The threat model considers the following assets:

For the purposes of DA-RDPS-001, Table R.1 identifies potential categories of RDPS interaction content and indicates the security properties to be considered for each category when determining the applicable Annex R requirement families.

Table R.1: Security properties for DA-RDPS-001
**Table R.1: Security properties for DA-RDPS-001**

| Content type                                | Data authenticity | Integrity | Confidentiality |
|:--------------------------------------------|:-----------------:|:---------:|:---------------:|
@@ -73,7 +73,7 @@ Table R.1: Security properties for DA-RDPS-001

For the purposes of DA-RDPS-002, Table R.2 identifies the security property relevant to the RDPS-dependent product function.

Table R.2: Security property for DA-RDPS-002
**Table R.2: Security property for DA-RDPS-002**

| Content type                    | Availability |
|:--------------------------------|:------------:|
@@ -127,7 +127,7 @@ The local product side or the RDPS side is unable to send, receive, or process i

### R.3.4 Assets to Threats mapping

Table R.3: Assets to Threats mapping
**Table R.3: Assets to Threats mapping**

| Threat ID | Threat title                                                                                            | Related asset(s) |
|:----------|:--------------------------------------------------------------------------------------------------------|:-----------------|
@@ -228,7 +228,7 @@ The RDPS side shall detect unavailability of the local product side or unaccepta

### R.4.4 Threats ↔ Requirements mapping

Table R.4: Threats ↔ Requirements mapping
**Table R.4: Threats ↔ Requirements mapping**

| Threat ID | Requirement(s) – Local product side | Requirement(s) – RDPS side |
|-----------|-------------------------------------|----------------------------|
@@ -563,7 +563,7 @@ Fail:

The table below identifies the CRA Annex I Part I requirements that are directly relevant to the RDPS boundary and maps each to the corresponding Annex R requirements. The purpose of this mapping is to support manufacturer traceability and to identify directly relevant CRA requirements that are not yet fully covered by the current Annex R draft. Requirements not covered by Annex R remain addressed by the core part of the standard, insofar as those requirements apply to the product as a whole.

Table R.5: CRA Annex I Part I ↔ Annex R requirements mapping
**Table R.5: CRA Annex I Part I ↔ Annex R requirements mapping**

| CRA Annex        | CRA text (summary)                                                                                                                                                                                                                                           | Annex R mapping                                                                                                                                                                                                                                                               | Rationale / gap observation                                                                                                                                                                                                                                                                                                                |
|------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|