Verified Commit 9c582439 authored by Aki Braun's avatar Aki Braun
Browse files

Remove some boilerplate

move last examples of "concentrator"
remove some boilerplate
Move references to the bibliography
parent 6292a663
Loading
Loading
Loading
Loading
+17 −27
Original line number Diff line number Diff line
@@ -164,24 +164,21 @@ This includes products whose use cases are focused on enterprise workforce deplo

1. Software that operates as a VPN server or gateway
1. Software that operates as a VPN client or end-point
1. Software for managing the configuration of the VPN and its clients, including authentication
1. Software for managing the configuration of the VPN and its end-points, including authentication
1. Remote data processing for services associated with enterprise VPNs

This standard explicitly excludes VPNs used in the industrial OT domain, as mentioned in CRA Annex III Class I important products, which are covered in EN 62443-5-XX.

## 1.2 Products in scope

> Detailed list of things that are in scope, to help manufacturers identify in-scope products. Make the scope as narrow as possible while still covering all products in the vertical. Use the latest draft of the technical descriptions to help. Technical experts are considered to be the authority for interpreting the meaning and definition of technical terms, so use your best technical judgement.

The scope of this standard covers products intended for enterprise, business, or institutional use cases, specifically for remote workforce access or secure network-to-network connections. It applies to both standalone products and those that are part of a larger security platform.

This includes:

- Software:
  - Software that operates as an enterprise-grade virtual private network server, gateway, or concentrator.
  - VPN client software intended for installation on end-user devices for distributed workers connecting to a remote private network.
- Hardware:
  - Commercially available hardware appliances whose intended purpose is to perform the duties of a VPN server, gateway, or concentrator for an enterprise network.
  - Software that operates as an enterprise-grade virtual private network server or gateway.
  - VPN end-point software intended for installation on end-user devices, typically for workers connecting to a remote private network.
  - VPN software acting as an end-point or server intended for connecting data centres or on-premises server hardware
- Remote Data Processing:
  - Cloud-based services or remote data processing solutions that are essential for the operation of an enterprise VPN, such as authentication services, policy enforcement, and management portals.

@@ -189,15 +186,12 @@ This part of the standard explicitly excludes consumer VPN services and VPNs use

## 1.3 Products not in scope

> Detailed list of things whose scope might be confusing, including parts of a system which are often included when the terms in the "in scope" section are used in general conversation. Reference the "Product Context" section again to remind the reader what operational environments are in scope.

This list clarifies products whose functionality might be confused with the in-scope products of this standard, but which are excluded due to their primary purpose or operational environment. This standard does not cover products in use in contexts other than those identified in Annex <L>.

- Consumer VPN services: Products with an intended purpose of providing a VPN for a single user or home network to connect to a public network are not in the scope of this standard, as they are covered in a separate document.
- VPNs for industrial OT domains: Products with digital elements intended for use in the industrial OT (Operational Technology) domain are explicitly excluded from this standard, as their security requirements are covered under a different standard (EN 62443-5-XX).
- Products with a VPN as a component: Products whose core purpose is not a VPN, but which contain VPN functionality, cannot rely on this standard alone for a presumption of conformity. This includes products like:
  - Firewalls and routers. While these devices may have integrated VPN capabilities, their primary function is network traffic control, which is addressed by other standards.
- VPN services without a provided client: Commercial actors that provide a VPN service solely by giving users configuration details (e.g., an OpenVPN config file) and do not provide an associated end-user client or managed hardware are not in scope.
- Products with a VPN as a component: Products whose core purpose is not a VPN, but which contain VPN functionality, cannot rely on this standard alone for a presumption of conformity. This includes products such as firewalls and routers. While these devices may have integrated VPN capabilities, their primary function is network traffic control, which is addressed by other standards.
- VPN services without a provided client: Commercial actors that provide a VPN service solely by giving users configuration details (e.g., an OpenVPN config file) and do not provide associated end-user software are not in scope.
- Unsecured network connections: This standard does not apply to software or hardware intended to link two or more networks without implementing a secure connection.

# 2 References
@@ -220,13 +214,14 @@ This list clarifies products whose functionality might be confused with the in-s

The following referenced documents are necessary for the application of the present document.

- <a name="_ref_1">[1]</a> &lt;Standard Organization acronym> &lt;document number> (&lt;version number>): "&lt;Title>".
[//]: # (- <a name="_ref_1">[1]</a> &lt;Standard Organization acronym> &lt;document number> (&lt;version number>): "&lt;Title>".)

* <a name="_ref_1">[1]</a>    CEN ## (##): “Cybersecurity requirements for products with digital elements — General principles for cyber resilience”
* <a name="_ref_2">[2]</a>    CEN ## (##): “Cybersecurity requirements for products with digital elements — Vulnerability Handling”
* <a name="_ref_1">[3]</a>	  CEN ## (##): TK possible vocabulary document from WG9
* <a name="_ref_1">[4]</a>    ETSI ## (##): TK shared vocabulary document from WG9
* <a name="_ref_1">[5-N]</a>  TK TODO related verticals, horizontals

[//]: # (* <a name="_ref_1">[3]</a>	  CEN ## (##): TK possible vocabulary document from WG9)

[//]: # (* <a name="_ref_1">[4]</a>    ETSI ## (##): TK shared vocabulary document from WG9)

[EDRs]: https://portal.etsi.org/Services/editHelp!/Howtostart/ETSIDraftingRules.aspx
[ETSI docbox]: https://docbox.etsi.org/Reference/
@@ -235,20 +230,15 @@ The following referenced documents are necessary for the application of the pres

References are either specific (identified by date of publication and/or edition number or version number) or nonspecific. For specific references, only the cited version applies. For non-specific references, the latest version of the referenced document (including any amendments) applies.

> - <a name="_ref_i.1">[i.1]</a> &lt;Standard Organization acronym> &lt;document number> (&lt;version number>): "&lt;Title>".
> - or as defined in [References in ETSI Deliverables][References]

> NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee their long-term validity.

The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's understanding but are not required for conformance to the present document.

* <a name="_ref_i.0">[i.0]</a>    &lt;Standard Organization acronym> &lt;document number> (&lt;version number>): "&lt;Title>".
[//]: # (* <a name="_ref_i.0">[i.0]</a>    &lt;Standard Organization acronym> &lt;document number> &#40;&lt;version number>&#41;: "&lt;Title>".)

* <a name="_ref_i.1">[i.1]</a>    Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
* <a name="_ref_i.2">[i.2]</a>    Commission Implementing Regulation (EU) TKTK TODO on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 of the European Parliament and of the Council (Text with EEA relevance)
* <a name="_ref_i.3">[i.3]</a>    CLC EN 62443-5-XX (): “Security Profile for network management systems”
* <a name="_ref_i.4">[i.4]</a>    Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act)
* <a name="_ref_i.5">[i.5]</a>    ITU-T Y.1311 (03/2002): "Network-based VPNs – Generic architecture and service requirements".

[References]: https://portal.etsi.org/Portals/0/TBpages/edithelp/Docs/News_from_editHelp/References_in_ETSI_deliverables.pdf

@@ -325,8 +315,6 @@ The following types of products have reduced or varied requirements under Regula

## 4.X Product overview and architecture

> Explain the overall architecture and relationship among the parts of the products. Use diagrams if that is helpful.

### 4.X.1 Product overview

As a holistic product, a Virtual Private Network includes, at minimum, VPN software capable of establishing a secure encrypted tunnel on two or more devices. VPN products also provide management capabilities to network administrators: user and group management, access control, logging and monitoring.
@@ -351,13 +339,13 @@ VPN client is a piece of software responsible for connecting a single end-point

After establishing a tunnel, the VPN client changes configuration of the operating system to facilitate connections to the private network - this can include changes to DNS configuration, firewall rules, routing table, etc. This configuration is tailored to the end-user, and is based on a combination of local user preferences and policies configured centrally by the network administrator.

### 4.X.4 VPN server, VPN gateway, VPN concentrator
### 4.X.4 VPN server, VPN gateway

A VPN server is responsible for maintaining tunnels with VPN clients, acting as a gateway to the private network for those clients.

### 4.X.5 Management server

Management server provides a way for network administrators to control configuration and membership of their network. This can include:
A VPN management server provides a way for network administrators to control configuration and membership of their network. This can include:

* Identity and authentication: management of users and groups, authentication credentials.
* Access control: policies that permit or deny certain traffic within the network.
@@ -826,6 +814,8 @@ Other Union legislation may be applicable to the product(s) falling within the s

&lt;Publication>: "&lt;Title>".&lt;Edition>. &lt;Year>, &lt;Issue designation>, &lt;Page location>.

ITU-T Y.1311 (03/2002): "Network-based VPNs – Generic architecture and service requirements".

# Annex &lt;L+4> (informative): Change history

The "Change history/Change request (history)" annex shall be included in every revised or amended harmonised standard and shall contain information concerning significant changes that have been introduced by it. It shall be presented as a table.