Update applicability statements for secure update.
- indicate each applies to the specific scenario in the requirement itself
- create separate lists in the security analysis
- update the ESR mapping table
Closes #541
@@ -177,14 +177,8 @@ This requirement applies to the subset of products in the indicated use cases wh
### 5.5.1 Overview
#### 5.5.1.1 CRA relevance
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (c).
#### 5.5.1.2 Guidance for updates before or during first use (MI-KEVA, MI-KEVE)
Recognizing that there may be vulnerabilities discovered between the time that a product is placed on the market and the time of that product's first use, and that the product should be free from known exploitable vulnerabilities both when first made available and when first used by a consumer, the product should be able to be updated at the time of first use to address known exploitable vulnerabilities which were discovered after the product's placement on the market and before first use.
### 5.5.3 REQ-SU-03 (MI-KEVA) Automatic secure update before or during first use
#### 5.5.3.1 Requirement
@@ -211,9 +205,7 @@ The product shall implement secure update via the operational environment before
#### 5.5.4.2 Applicability
This requirement applies to the subset of products within the indicated use cases where updates are managed by the operational environment and not by the product itself.
> NOTE: Enterprise customers may have a business need to either delay or force updates to any node with access to a private network.
This requirement applies to the subset of products within the indicated use cases that have security updates applied via the operational environment, such as the operating system itself, an “app store”, or some external platform.
* UC-1: required
* UC-2: required
@@ -237,7 +229,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-2: not required
* UC-3: not required
* UC-4: not required
* UC-5: REQ-SU-05 (MI-SUVP) OR REQ-SU-06 (MI-SUAP) OR REQ-SU-08 (MI-SUOE) OR REQ-SU-09 (MI-SUAO)
* UC-5: REQ-SU-05 (MI-SUVP) OR REQ-SU-06 (MI-SUAP)
* UC-6: not required
* UC-7: not required
@@ -248,6 +240,8 @@ This requirement applies to the subset of products within the indicated use case
1.**REQ-SU-06 (MI-SUAP)-1** The product shall provide a method of automatically securely updating any software in the product via the product itself, and
2.**REQ-SU-06 (MI-SUAP)-2** the product shall provide an option for the administrating user to disable or defer automatic updates.
> NOTE: Enterprise customers may have a business need to either delay or force updates to any node with access to a private network.
#### 5.5.6.2 Applicability
This requirement applies to the subset of products within the indicated use cases that have the capability to self-update, i.e. not distributed by an “app store” or package distribution platform that manages all updates.
@@ -256,7 +250,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: REQ-SU-05 (MI-SUVP) OR REQ-SU-06 (MI-SUAP) OR REQ-SU-08 (MI-SUOE) OR REQ-SU-09 (MI-SUAO)
* UC-5: REQ-SU-05 (MI-SUVP) OR REQ-SU-06 (MI-SUAP)
* UC-6: required
* UC-7: required
@@ -274,7 +268,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-2: not required
* UC-3: not required
* UC-4: not required
* UC-5: REQ-SU-05 (MI-SUVP) OR REQ-SU-06 (MI-SUAP) OR REQ-SU-08 (MI-SUOE) OR REQ-SU-09 (MI-SUAO)
* UC-5: REQ-SU-08 (MI-SUOE) OR REQ-SU-09 (MI-SUAO)
* UC-6: not required
* UC-7: not required
@@ -284,17 +278,19 @@ This requirement applies to the subset of products within the indicated use case
The user documentation provided with the product shall document that the operational environment provides a method of automatically securely updating the product with an option for the product to be configured to disable automatic updates.
> NOTE: Enterprise customers may have a business need to either delay or force updates to any node with access to a private network.
#### 5.5.9.2 Applicability
This requirement applies to the subset of products within the indicated use cases that have security updates applied via the operational environment, such as the operating system itself, an “app store”, or some external platform.
* UC-1: not required
* UC-2: not required
* UC-3: not required
* UC-4: not required
* UC-5: REQ-SU-05 (MI-SUVP) OR REQ-SU-06 (MI-SUAP) OR REQ-SU-08 (MI-SUOE) OR REQ-SU-09 (MI-SUAO)
* UC-6: not required
* UC-7: not required
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: REQ-SU-08 (MI-SUOE) OR REQ-SU-09 (MI-SUAO)
* UC-6: required
* UC-7: required
### 5.5.10 REQ-SU-10 (MI-SUCS) Updates are signed and verified before installation
@@ -468,12 +464,12 @@ The product shall reject Repository Metadata if its version number is equal to o