@@ -146,7 +146,7 @@ In the present document "**shall** ", "**shall not** ", "**should** ", "**should
# Executive summary
The purpose of this document is to provide essential cybersecurity requirements for the design, development, and production of Virtual Private Networks intending to be placed on the European Union market. By demonstrating conformity with the present document's requirements, manufacturers of VPNs benefit from a presumption of conformity with Regulation (EU) 2024/2847 of the European Parliament and of the Council, colloquially known as the Cyber Resiliance Act.
The purpose of this document is to provide essential cybersecurity requirements for the design, development, and production of Virtual Private Networks intending to be placed on the European Union market. By demonstrating conformity with the present document's requirements, manufacturers of VPNs benefit from a presumption of conformity with Regulation (EU) 2024/2847 of the European Parliament and of the Council, colloquially known as the Cyber Resilience Act.
# Introduction
@@ -288,6 +288,10 @@ For the purposes of the present document, the terms given in [TK document from C
'software bill of materials' means a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements;
'on-premises infrastructure' means the collection of servers, switches, and other hardware used to connect company-owned resources to internal and external networks. Unless specified otherwise, applies to equipment located within a corporate campus, inside of a multi-tenant data centre, inside of a single tenant data centre, or any combination of the three.
'cloud' means a data centre or collection of data centres operated entirely by a third party which rents out space and time on their equipment, as well as providing services for managing infrastructure from outside networks.
## 3.2 Abbreviations
For the purposes of the present document, abbreviations given in [TK document from CEN-CENELEC WG9], [TK document from STF701] and the following apply:
@@ -307,7 +311,7 @@ For the purposes of the present document, abbreviations given in [TK document fr
The types of product with digital elements listed in the section do not fall within the scope of the the Regulation (EU) 2024/2847 (Cyber Resilience Act), and are not covered by this standard:
1. Services, except for the remote data processing solutions for a covered product as defined in CRA recitals 11-12; article 3, 2 <ahref="#_ref_i.1">[i.1]</a>;
2. Products specifically designed or procured for national security and defence purpose as defined in CRA recitals 14 and 26; article 2, 7-8 <ahref="#_ref_i.1">[i.1]</a>;
2. Products developed or modified for national security and defence purpose, or for processing classified material, as defined in CRA recitals 14 and 26; article 2, 7-8 <ahref="#_ref_i.1">[i.1]</a>;
3. Products developed for or used exclusively for internal use by public administration as defined in CRA recital 16; article 5, 2 <ahref="#_ref_i.1">[i.1]</a>;
4. Non-commercial free and open source software as defined in CRA recitals 17-21; article 13, 5 <ahref="#_ref_i.1">[i.1]</a>;
5. Medical Devices and Software as defined in CRA recital 25; article 2, 2 [a-b] <ahref="#_ref_i.1">[i.1]</a>;
@@ -333,11 +337,11 @@ As a holistic product, a Virtual Private Network includes, at minimum, VPN clien
### 4.2.2 Architecture
Virtual Private Networks can differ in topologies used to transmit data and distribute configuration. Two common distinct topologies are hub-and-spoke networks and mesh networks; in practice, networks can use more complex mixed topologies that fall somewhere in between the two extemes.
Virtual Private Networks can differ in topologies used to transmit data and distribute configuration. Two common distinct topologies are hub-and-spoke networks and mesh networks; in practice, networks can use more complex mixed topologies that fall somewhere in between the two extremes.
In a hub-and-spoke network, multiple clients connect to a single VPN server/gateway, which provides both management and routing capabilities to the clients.


In a mesh network, clients and gateways establish direct tunnels between each other. A management server is used to authenticate VPN clients and gateways, and to configure them.
@@ -361,7 +365,7 @@ Management server provides a way for network administrators to control configura
* Access control: policies that permit or deny certain traffic within the network.
* Monitoring and logging: configuration logs, network logs, telemetry used for troubleshooting.
Management server typically mantains configuration of the whole network, and provides configuration to individual clients as they connect (authentication, address assignment, routes, etc).
Management server typically maintains configuration of the whole network, and provides configuration to individual clients as they connect (authentication, address assignment, routes, etc).
In VPNs using a hub-and-spoke topology, management server is often implemented as part of the VPN server.
@@ -375,61 +379,155 @@ In VPNs using a hub-and-spoke topology, management server is often implemented a
This list of use cases is an informative resource to the manufacturer to simplify choosing a set of security requirements. Each use case is mapped to a security level, which is a collection of risks and the security requirements necessary to mitigate them.
### 4.4.2 VPN software intended for enterprise workforce deployment
XXX VPN client software
XXX VPN server software
——
/ | XXXX enterprise hardware
risk / | XXXX enterprise-controlled cloud
transfer \ | XXXX manufacturer hardware
\ | XXXX manufacturer cloud
——
XXX VPN management
### 4.X.X VPN clients
All VPN clients carry with them the inherent risk of being the entry point to a private network.
***UC-UR-1** Small business staff accessing office resources from off-site
* connections likely brief, task-driven
* endpoint hardware is unmanaged
***UC-US-2** Students accessing university resources off-campus
***AUT-L-1** Restricted to devices fully managed by enterprise MDM
***AUT-L-2** Accessible by user-controlled hardware with a fully preconfigured VPN client
***AUT-L-3** Accessible by user-controlled hardware with user-selected VPN client
* Users with administrative access
***[ADM-L-0]** Restricted to limited IT professionals with a physical presence on the private network
***[ADM-L-N]** TK a description of a scenario where the VPN is entirely cloud-based so admin _cannot_ have a physical presence
***[ADM-L-N]** Administrators can access VPN management portal via the VPN
***ADM-L-0** Restricted to limited IT professionals with a physical presence on the private network
***ADM-L-N** TK a description of a scenario where the VPN is entirely cloud-based so admin _cannot_ have a physical presence
***ADM-L-N** Administrators can access VPN management portal via the VPN
* Physical access to data processing
***[PHY-L-N]**
***[PHY-L-N]**
***[PHY-L-N]**
***PHY-L-N**
***PHY-L-N**
***PHY-L-N**
### 4.5.1 Mapping of use cases to risk factors and security levels
| Use case | USR | CFG | AUT | ADM | Sec Lev |
|----------|-----|-----|-----|-----|---------|
| UC-TK-1 | L-0 | L-0 | L-1 | L-0 | SC-TK-1 |
### 4.5.1 Mapping of use cases to risk factors and security levels
## 4.6 Security levels
@@ -482,10 +580,10 @@ VPNs can be expected to operate in a network environment alongside other Importa
This section describes the different classes of users for VPN products, differentiating them by their security expertise, goals, and the threats they are most likely to face.
#### 4.8.1.2 Consumers
#### 4.8.1.2 University student
**USER-1**
: This user type is characterized as having low security expertise and utilizes VPN products for personal purposes on personal devices. Their expectation is for a simple, pre-configured product that requires minimal user intervention.
: This user type is not expected to have high security expertise and utilizes VPN products for accessing university resources while away from campus. Their expectation is for a simple, pre-configured product that requires minimal user intervention.