@@ -191,7 +191,7 @@ User interfaces, especially in regard to settings, shall be designed in a manner
#### 5.4.2.2 Applicability
This requirement applies to VPNs featuring user-installable software which includes a graphical user interface within the following use cases:
This requirement applies to the subset of products in the indicated use cases which include a graphical user interface.
* UC-1: required
* UC-2: required
@@ -227,9 +227,7 @@ The product shall implement automatic secure update before or during first use.
#### 5.5.3.2 Applicability
This requirement applies to any product that is capable of updating itself, i.e. is not distributed by an “app store” or package distribution platform that manages all updates.
Of those products, use-case applicability follows:
This requirement applies to the subset of products within the indicated use cases that have the capability to self-update, i.e. not distributed by an “app store” or package distribution platform that manages all updates.
* UC-1: REQ-SU-03 (MI-KEVA) or REQ-SU-02 (MI-KEVD) is required
* UC-2: required
@@ -247,7 +245,7 @@ The product shall implement secure update via administrator actions before or du
#### 5.5.4.2 Applicability
This requirement applies to scenarios where network infrastructure is managed by professional network administrator in an enterprise environment.
This requirement applies to the indicated use cases where network infrastructure is managed by professional network administrator in an enterprise environment.
> NOTE: Enterprise customers may have a business need to either delay or force updates to any node with access to a private network.
@@ -267,9 +265,7 @@ The product shall provide a method of securely updating any software in the prod
#### 5.5.5.2 Applicability
This requirement applies to any product that is capable of updating itself, i.e. is not distributed by an “app store” or package distribution platform that manages all updates.
Of those products, use-case applicability follows:
This requirement applies to the subset of products within the indicated use cases that have the capability to self-update, i.e. not distributed by an “app store” or package distribution platform that manages all updates.
* UC-1: REQ-SU-05 (MI-SUVP) or REQ-SU-06 (MI-SUAP) or REQ-SU-08 (MI-SUOE) or REQ-SU-09 (MI-SUAO) apply
* UC-2: not required
@@ -288,9 +284,7 @@ Of those products, use-case applicability follows:
#### 5.5.6.2 Applicability
This requirement applies to any product that is capable of updating itself, i.e. is not distributed by an “app store” or package distribution platform that manages all updates.
Of those products, use-case applicability follows:
This requirement applies to the subset of products within the indicated use cases that have the capability to self-update, i.e. not distributed by an “app store” or package distribution platform that manages all updates.
* UC-1: REQ-SU-06 (MI-SUAP) or REQ-SU-05 (MI-SUVP) or REQ-SU-08 (MI-SUOE) or REQ-SU-09 (MI-SUAO) apply
* UC-2: REQ-SU-06 (MI-SUAP) or REQ-SU-09 (MI-SUAO) apply
@@ -308,9 +302,7 @@ The technical documentation provided with the product shall document that the op
#### 5.5.8.2 Applicability
This requirement applies to products that have security updates applied via the operational environment, such as the operating system itself, an “app store”, or some external platform.
Of those products that receive security updates externally, use-case applicability follows:
This requirement applies to the subset of products within the indicated use cases that have security updates applied via the operational environment, such as the operating system itself, an “app store”, or some external platform.
* UC-1: REQ-SU-08 (MI-SUOE) or REQ-SU-05 (MI-SUVP) or REQ-SU-06 (MI-SUAP) or REQ-SU-09 (MI-SUAO) apply
* UC-2: not required
@@ -328,9 +320,7 @@ The user documentation provided with the product shall document that the operati
#### 5.5.9.2 Applicability
This requirement applies to products that have security updates applied via the operational environment, such as the operating system itself, an “app store”, or some external platform.
Of those products that receive security updates externally, use-case applicability follows:
This requirement applies to the subset of products within the indicated use cases that have security updates applied via the operational environment, such as the operating system itself, an “app store”, or some external platform.
* UC-1: REQ-SU-09 (MI-SUAO) or REQ-SU-05 (MI-SUVP) or REQ-SU-06 (MI-SUAP) or REQ-SU-08 (MI-SUOE) apply
* UC-2: REQ-SU-09 (MI-SUAO) or REQ-SU-06 (MI-SUAP) apply
@@ -349,7 +339,7 @@ Of those products that receive security updates externally, use-case applicabili
#### 5.5.10.2 Applicability
[//]:#(TODO detail applicability based on update channel?)
This requirement applies to the subset of products within the indicated use cases that have the capability to self-update, i.e. not distributed by an “app store” or package distribution platform that manages all updates.
* UC-1: not required
* UC-2: required
@@ -602,7 +592,7 @@ VPN server or mesh node shall detect when multiple VPN clients are using credent
#### 5.6.5.2 Applicability
This requirement applies to VPNs where the product handles credentials, VPN client credentials can be duplicated, and the product falls under following use cases:
This requirement applies to the subset of products within the indicated use cases that handle credentials and function in such a way that client credentials can be duplicated.
* UC-1: not required
* UC-2: not required
@@ -641,7 +631,7 @@ The product shall use credentials with at least 128 bit of entropy, or rate-limi
#### 5.6.7.2 Applicability
This requirement applies to products which do not transfer responsibility for rate-limiting to the operating environment which also fall within the following use cases:
This requirement applies to the subset of products within the indicated use cases which do not transfer responsibility for rate-limiting to the operating environment.
* UC-1: required
* UC-2: required
@@ -679,8 +669,6 @@ The VPN client shall support fine grant access control configuration to configur
#### 5.6.9.2 Applicability
This requirement applies to VPNs that utilize mesh networking.
* UC-1: not required
* UC-2: not required
* UC-3: not required
@@ -833,7 +821,7 @@ The VPN traffic shall be encrypted between the VPN client and the designated end
#### 5.7.7.2 Applicability
Products within the following use cases shall fulfill **at least one** of the above sub-requirements, REQ-CON-07 (MI-DNSL-2)-1, **or** REQ-CON-07 (MI-DNSL-2)-2.
Products within the indicated use cases shall fulfill **at least one** of the above sub-requirements, REQ-CON-07 (MI-DNSL-2)-1, **or** REQ-CON-07 (MI-DNSL-2)-2.
* UC-1: not required
* UC-2: required
@@ -867,7 +855,7 @@ The VPN client shall respond in a timely manner to changes to local configuratio
#### 5.7.9.2 Applicability
This requirement is only applicable if changes in the local DNS configuration would affect the plaintext DNS query visibility outside the tunnel to third parties of the system, and the product falls within the following use cases.
This requirement is applicable to products within the indicated use cases where changes in the local DNS configuration would affect the plaintext DNS query visibility outside the tunnel to third parties of the system.
* UC-1: not required
* UC-2: not required
@@ -1287,7 +1275,7 @@ The product shall support multiple nodes which act as possible alternative fallb
#### 5.10.6.2 Applicability
This requirement applies to all products within the below use cases, _except_ products which rely on a single node or dedicated IP address.
This requirement applies to all products within the indicated use cases unless the product relies on a single node or dedicated IP address.
* UC-1: not required
* UC-2: required
@@ -1525,7 +1513,7 @@ Products with the capability to transmit logs to remote data processing solution
#### 5.14.3.2 Applicability
This requirement is dependent on the product's intended use case, mandatory only for use cases where centralized log management is a standard security expectation.
This requirement applies to the subset of products within the indicated use cases where centralized log management is a standard security expectation.
* UC-1: not required
* UC-2: not required
@@ -1584,7 +1572,7 @@ VPNs are expected to provide the ability to securely delete data and settings, a
#### 5.15.2.2 Applicability
This requirement applies to products with the capability for the user to write data and/or settings that fall within the following use cases
This requirement applies to the subset of products within the indicated use cases with the capability for the user to write data and/or settings.
* UC-1: required
* UC-2: required
@@ -1602,7 +1590,7 @@ The product shall provide an option to restore its secure-by-default state durin
#### 5.15.3.2 Applicability
This requirement applies to products with the capability for the user to write data and/or settings that fall within the following use cases
This requirement applies to the subset of products within the indicated use cases with the capability for the user to write data and/or settings.
* UC-1: required
* UC-2: required
@@ -1620,7 +1608,7 @@ The VPN client shall provide a method by which an authorized user can securely r
#### 5.15.4.2 Applicability
This requirement applies to products with the capability for the user to write data and/or settings that fall within the following use cases
This requirement applies to the subset of products within the indicated use cases with the capability for the user to write data and/or settings.
* UC-1: not required
* UC-2: not required
@@ -1641,9 +1629,7 @@ This requirement applies to products with the capability for the user to write d
#### 5.15.5.2 Applicability
This requirement applies to products with the capability for the user to write data and/or settings, and product support of exporting of that data to an external file. This requirement is strictly applicable to use cases where an IT professional or advanced user can reasonably be expected to administer the product.
Of the above described products, this requirement applies to products that fall within the following use cases
This requirement applies to the subset of products within the indicated use cases with the capability for the user to write data and/or settings, and the capability to export that data to an external file. This requirement is strictly applicable to use cases where an IT professional or advanced user can reasonably be expected to administer the product.