Loading part 1 clause 5.md +14 −1 Original line number Diff line number Diff line # 5 Requirements specifications does split tunneling pose a security threat relevant to this document? maybe in the documentation section? ## 5.1 General ## 5.2 Technical security requirements specifications Loading Loading @@ -66,15 +68,21 @@ User-manageable VPN settings shall be configurable in a manner that introducing ## 5.5 [ACM] Authentication and access control mechanisms - Requirement: administrators must be able to revoke and regenerate credentials, individually or in bulk, in case of exploit - Disable remote access for administrators? - MFA, obviously ## 5.6 [TKTK] Integrity protection ## 5.7 [TKTK] Confidentiality protection ## 5.8 [TKTK] Data minimization Personal VPNs: don't log traffic activity Any logged traffic activity is subject to replay exposure Any logged traffic activity is subject to replay exposure, protect it jealously and rotate logs frequently ## 5.9 [TKTK] Availability protection Loading @@ -84,12 +92,17 @@ Go into enterprise security here, specifically describe potential mitigations th ## 5.11 [TKTK] Limit attack surface - rotate logs that may expose proprietary data frequently ## 5.12 [TKTK] Logging and monitoring mechanisms Basic level: DON'T Middle & Critical level: LOG CONFIG CHANGES - log access attempts - log config changes ## 5.13 [TKTK] Deletion mechanisms ## 5.12 [TKTK] Other product's technical requirements specifications Loading
part 1 clause 5.md +14 −1 Original line number Diff line number Diff line # 5 Requirements specifications does split tunneling pose a security threat relevant to this document? maybe in the documentation section? ## 5.1 General ## 5.2 Technical security requirements specifications Loading Loading @@ -66,15 +68,21 @@ User-manageable VPN settings shall be configurable in a manner that introducing ## 5.5 [ACM] Authentication and access control mechanisms - Requirement: administrators must be able to revoke and regenerate credentials, individually or in bulk, in case of exploit - Disable remote access for administrators? - MFA, obviously ## 5.6 [TKTK] Integrity protection ## 5.7 [TKTK] Confidentiality protection ## 5.8 [TKTK] Data minimization Personal VPNs: don't log traffic activity Any logged traffic activity is subject to replay exposure Any logged traffic activity is subject to replay exposure, protect it jealously and rotate logs frequently ## 5.9 [TKTK] Availability protection Loading @@ -84,12 +92,17 @@ Go into enterprise security here, specifically describe potential mitigations th ## 5.11 [TKTK] Limit attack surface - rotate logs that may expose proprietary data frequently ## 5.12 [TKTK] Logging and monitoring mechanisms Basic level: DON'T Middle & Critical level: LOG CONFIG CHANGES - log access attempts - log config changes ## 5.13 [TKTK] Deletion mechanisms ## 5.12 [TKTK] Other product's technical requirements specifications