Unverified Commit 96c140a1 authored by Aki Braun's avatar Aki Braun
Browse files

Added content addressing software security

parent c1fb4bd0
Loading
Loading
Loading
Loading
+7 −4
Original line number Diff line number Diff line

**Draft ETSI EN 304 620 v0.0.6 (2025-09)**
**Draft ETSI EN 304 620 v0.0.6 Part 1 (2025-09)**

![~~CAPTION~~](media/etsi-coverpage-logo.png)

@@ -209,6 +209,8 @@ The following referenced documents are necessary for the application of the pres

* <a name="_ref_1">[1]</a>    CEN ## (##): “Cybersecurity requirements for products with digital elements — General principles for cyber resilience”
* <a name="_ref_2">[2]</a>    CEN ## (##): “Cybersecurity requirements for products with digital elements — Vulnerability Handling”
* <a name="_ref_3">[3]</a>    OWASP ASVS (v5.0.0): “Application Security Verification Standard”
* <a name="_ref_4">[4]</a>    OWASP MASVS (v2.1.0): “Mobile Application Security Verification Standard”

[//]: # (* <a name="_ref_1">[3]</a> CEN ## (##): TK possible vocabulary document from WG9)
[//]: # (* <a name="_ref_1">[4]</a> ETSI ## (##): TK shared vocabulary document from WG EUSR)
@@ -339,7 +341,7 @@ The following types of products have reduced or varied requirements under Regula

### 4.2.1 Product overview

For the purpose of this document, a VPN is a product with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network, including cases where that product provides access from a restricted-use logical computer network to a public network.
For the purpose of the current document, a VPN is a product with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network, including cases where that product provides access from a restricted-use logical computer network to a public network.

As a holistic product, a Virtual Private Network includes, at minimum, VPN software capable of establishing a secure encrypted tunnel between two or more devices. VPN products also provide management capabilities to network administrators: user and group management, access control, logging and monitoring.

@@ -696,8 +698,6 @@ The VPN product offers the following security functionalities to other component

### C.1.1 Data

> What data is stored on the product?

- Data transmitted over the VPN network
- Management and configuration data
  - Configuration data
@@ -708,6 +708,9 @@ The VPN product offers the following security functionalities to other component
  - Network configuration audit logs
  - Network flow logs and other statistics about data transferred over the network
  - Debugging logs from end-points and VPN gateways
- Software applications
  - Product management web application (including web server and browser-based UI)
  - Device-native applications for connecting to the network (Client or Node software)

### C.1.2 Product functions