Verified Commit d50c9ebc authored by Aki Braun's avatar Aki Braun
Browse files

Annex C start

parent d3b4a634
Loading
Loading
Loading
Loading
+17 −2
Original line number Diff line number Diff line
@@ -621,10 +621,22 @@ This table maps the user types to the corresponding use cases and the security l

> What data is stored on the product?

- Activity logs
- Configuration data

### C.1.2 Product functions

> See the functions in Section 4.4.

TODO delete and reference clause 4 or reword

* Edge - uses a public network to communicate with the restricted use network
* Gateway - provides link between public network and restricted
* Router - forward traffic between nodes in the restricted use network
* Filter - select which traffic may transit this node
* Relays - assist nodes in connecting to the restricted use network
* Auth - grant nodes access to the restricted network

## C.2 Threats

> Based on the assets, what are the threats during:
@@ -634,6 +646,11 @@ This table maps the user types to the corresponding use cases and the security l

> Example threats can be found in the same documents suggested in the section on security requirements.
 
- Untrusted traffic gaining access using illicitly acquired configuration data
- Endpoint malware hijacking traffic or recording activity
- Social engineering resulting in credential harvesting
- 

## C.3 Assumptions

> List assumptions that are relevant to the risk analysis for these threats. Everything is hackable if you try hard enough. What kinds of threats are in and out of scope? What are you assuming is the sophistication of attack? Relate to use cases.
@@ -656,8 +673,6 @@ This table maps the user types to the corresponding use cases and the security l

> NOTE 3 A quantitative estimation of the cybersecurity risks can be performed using scoring systems that map qualitative categories of the likelihood of occurrence and qualitative categories of magnitude of loss or disruption to certain values.



# Annex D (informative): Risk evaluation guidance

## D.1 Mapping of risks to requirements