Commit 9a273836 authored by Joseph Rotolo's avatar Joseph Rotolo Committed by Aki Braun
Browse files

Part1 - Updating section 4.7 Users

parent 64522e8e
Loading
Loading
Loading
Loading
+60 −7
Original line number Diff line number Diff line
@@ -366,13 +366,66 @@ Expected use-cases include Hospitals, financial institutions, high-risk individu

## 4.8 Users

> Describe the classes of users for this product, as differentiated by sophistication in understanding and taking responsibility for security risks. More sophisticated users can be expected to follow more instructions and cope with higher levels of unmitigated risks. Suggestions:
>
> * General public
> * Children
> * Assistants to primary user
> * IT professionals
> * Systems integrators
### 4.8.1 User Types and Descriptions

#### 4.8.1.1 Overview

This section describes the different classes of users for VPN products, differentiating them by their security expertise, goals, and the threats they are most likely to face.

#### 4.8.1.2 Consumers

This user type is characterized as having low security expertise and utilizes VPN products for personal purposes on personal devices. Their expectation is for a simple, pre-configured product that requires minimal user intervention.

#### 4.8.1.3 Enterprise IT / Administrators

This user type is composed of professionals with high technical and security expertise. The responsibilities of this group include the procurement, deployment, and management of VPN products within a corporate or institutional environment. This user type is responsible for establishing and maintaining secure connectivity, access controls, and security policies to protect corporate assets, intellectual property, and user data.

#### 4.8.1.4 Distributed Workers

This user type consists of employees or contractors of an organization who perform job duties from a remote location. They are end-users of an enterprise VPN and require a reliable and secure connection to the corporate network to access resources and handle sensitive information. The security posture of their VPN client is managed and enforced by the Enterprise IT team.

#### 4.8.1.5 Software Operations & Development

This user type comprises highly technical individuals who manage secure connections between data centers, cloud environments, or other technical infrastructure. The primary goal of this group is to ensure secure and high-performance data transfer for critical operational workflows. This user type is responsible for the implementation and maintenance of VPNs utilized for managing sensitive data and intellectual property.

#### 4.8.1.6 High-Risk & Advanced Users

This user type is associated with individuals or organizations that are potential targets of sophisticated and high-resource adversaries. These users require a VPN product that provides the highest level of security and anonymity, and they are assumed to have advanced security knowledge to configure and manage the product's features.

### 4.8.2 User Needs by Security Level (Pending Security Levels Definition)

#### 4.8.2.1 Overview
The different user types have varying needs that correspond directly to the security levels defined in this standard. A manufacturer should take these into account to ensure the product's security is proportionate to its intended use.

#### 4.8.2.2 Base Security

**User**: Consumers

**Needs**: Easy to install and use, "secure by default" configuration, minimal user intervention, and reliable privacy protection against low-sophistication threats on untrusted public networks. Logging should be minimal, if it exists at all.

#### 4.8.2.3 General Security

**Users**: Enterprise IT and Distributed Workers

**Needs**: A centrally managed and configurable solution. Enterprise IT needs robust authentication and access control, logging of configuration changes, and integration with other security tools like firewalls and logging services. Distributed Workers need a secure and reliable client that enforces corporate policies without requiring a high degree of technical knowledge from the end-user.

#### 4.8.2.4 Critical Security

**Users**: Software Operations & Development and High-Risk & Advanced Users

**Needs**: This level requires the highest standards of security. Users need a VPN solution that provides advanced cryptographic protection, resistance to sophisticated attacks, and auditable logging of all relevant activities. For technical operations, it must support high-performance, resilient connections between data centers. For high-risk individuals, it must offer strong anonymity and protection against state-level adversaries.

### 4.8.3 User Needs and Associated Security Levels (TBD)

This table maps the user types to the corresponding use cases and the security levels required to meet their needs. This mapping serves as a basis for defining conditional or advanced requirements.

| User Type                         | Associated Use Case(s)                           | Security Level    |
|-----------------------------------|--------------------------------------------------|-------------------|
| Consumers                         | Consumer VPN service                             | Base Security     |
| Enterprise IT / Administrators    | VPN software for enterprise workforce deployment | General Security  |
| Distributed Workers               | VPN software for enterprise workforce deployment | General Security  |
| Software Operations & Development | VPN software connecting data centres             | Critical Security |
| High-Risk & Advanced Users        | Commercial VPN service for high-risk targets     | Critical Security |

## 4.9 Risk distribution among components