Unverified Commit 9de4c13b authored by Aki 🌹's avatar Aki 🌹
Browse files

Add some bullets to scope

parent b024a05a
Loading
Loading
Loading
Loading
+31 −36
Original line number Diff line number Diff line
@@ -143,46 +143,54 @@ In the present document "**shall** ", "**shall not** ", "**should** ", "**should

# Introduction

> A brief summary of the document to help the manufacturer figure out if they need to keep reading or if they should move on to a different document.

The present document is a European harmonised standard that defines cybersecurity requirements for products whose primary purpose is [describe vertical]. Demonstrating compliance with this standard is not necessary, but doing so provides a presumption of conformity with Regulation (EU) 2024/2847, the Cyber Resilience Act.

This standard does not apply to products that contain [vertical] or are part of [vertical] if the core purpose of the product is not that of an [vertical]. However, it may be useful as one part of the process of demonstrating compliance for a product containing or interacting with [vertical].
The present document is a European harmonised standard that defines cybersecurity requirements for products with digital elements whose primary purpose is connecting private networks with public networks or other private networks. Demonstrating compliance with this standard is not necessary, but doing so provides a presumption of conformity with Regulation (EU) 2024/2847, the Cyber Resilience Act.

This standard does not apply to products that have VPN capabilities as a feature of a broader holistic networking or security product, though it may be useful as one part of the process of demonstrating compliance for a product containing or interacting with VPNs.

# 1 Scope

# 1.1 General

The present document describes how to demonstrate compliance with requirements in the EU Regulation 2024/2847 under the conditions identified in Annex <L> of the following types of [equipment/software]:

The present document provides security requirements and assessment criteria covering all elements defined in EU Regulation 2024/2847 Cyber Resilience Act Annex I Part 1 and Part 2 for products with digital elements (products) with the intended purpose or reasonably foreseeable use of virtual private networks (VPN), excluding VPNs used in the industrial OT domain, as mentioned in CRA Annex III Class I important products.
These products include:
The present document describes how to demonstrate compliance with requirements in the EU Regulation 2024/2847 under the conditions identified in Annex <L> of the following types of software:

1)	Software that operates as a virtual private network server, gateway, or concentrator
2)	Software that operates as a virtual private network client
3)	Hardware that is commercially available that has the intended purpose of performing the duties of a virtual private network server or client
4)	Remote data processing for services associated with virtual private networks
      For the purpose of this document, a virtual private network is a product with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network, including cases where products provide access from a restricted-use logical computer network to the public internet.
      Cyber Resilience Act security requirements for VPNs in the industrial OT domain are covered in EN 62443-5-XX.
      TK Part 2 of this document describes security requirements for products that provide access to a restricted-use logical computer network without encryption using other methods to secure that traffic.
3)	Remote data processing for services associated with virtual private networks

For the purpose of this document, a virtual private network is a product with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network, including cases where products provide access from a restricted-use logical computer network to the public internet.
Cyber Resilience Act security requirements for VPNs in the industrial OT domain are covered in EN 62443-5-XX.
TK Part 2 of this document describes security requirements for products that provide access to a restricted-use logical computer network without encryption using other methods to secure that traffic.
within the context described in section 4, Product Context.
 
For the purpose of this document, a virtual private network, or _VPN_, is a product with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network, including cases where products provide access from a restricted-use logical computer network to a public network.

# 1.2 Products in scope

> Detailed list of things that are in scope, to help manufacturers identify in-scope products. Make the scope as narrow as possible while still covering all products in the vertical. Use the latest draft of the technical descriptions to help. Technical experts are considered to be the authority for interpreting the meaning and definition of technical terms, so use your best technical judgement.

- software that establishes a tunnel between other networks
- software that establishes a tunnel between a private network and an end-point
- Software which enables end users to connect to a protected network, frequently the internal network of an enterprise
- TKTK the business/enterprise version of a consumer VPN service is in scope, bc again it generally does not protect traffic between vpn server and its final destination 


# 1.3 Products not in scope

> Detailed list of things whose scope might be confusing, including parts of a system which are often included when the terms in the "in scope" section are used in general conversation. Reference the "Product Context" section again to remind the reader what operational environments are in scope.

This standard does not cover products in use in contexts other than those identified in Annex <L>.

- VPN services which provide a client for a consumer to connect to company-controlled servers
- Firewalls
- Routers
- zero-trust architecture

Cyber Resilience Act security requirements for VPNs in the industrial OT domain are covered in EN 62443-5-XX.

TK Part 2 of this document describes security requirements for products that provide access to a restricted-use logical computer network without encryption using other methods to secure that traffic.


Cyber Resilience Act security requirements for VPNs in the industrial OT domain are covered in EN 62443-5-XX.

TK Part 2 of this document describes security requirements for products that provide access to a restricted-use logical computer network without encryption using other methods to secure that traffic.


# 2 References

@@ -233,9 +241,6 @@ The following referenced documents may be useful in implementing an ETSI deliver
* <a name="_ref_i.3">[i.3]</a>    CLC EN 62443-5-XX (): “Security Profile for network management systems”
* <a name="_ref_i.4">[i.4]</a>    Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act)




# 3 Definition of terms, symbols and abbreviations

## 3.1 Terms
@@ -272,25 +277,15 @@ For the purposes of the present document, the terms given in [TK document from C

'software bill of materials' means a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements;



## 3.3 Abbreviations

For the purposes of the present document, abbreviations given in TKTK wg9 & STF701 vocabulary documents, TKTK probably TODO and the following apply:

TODO
For the purposes of the present document, abbreviations given in [TK document from CEN-CENELEC WG9], [TK document from STF701] and the following apply:

| Abbreviation | Description                  |
| ------------ | ----------------- |
| ABC          | Alphabets         |
| DEF          | More Alphabets    |

CRA    Cyber Resilience Act

VPN    Virtual Private Network

PwDE    Products with Digital Elements

|--------------|------------------------------|
| CRA          | Cyber Resilience Act         |
| VPN          | Virtual Private Network      |
| PwDE         | Product with Digital Element |

# 4 Product context