@@ -295,13 +295,7 @@ For the purposes of the present document, abbreviations given in [TK document fr
# 4 Product context
## 4.1 General
> NOTE: This section's structure is built upon CEN/CLC JTC13 PT01's deliverable and might require restructuring based on its progress.
## 4.2 Out of scope use/environments
> List uses/environments covered by other legislation or standards (critical, industrial, medical, etc.). Hoping to have a reusable generic list of these soon.
## 4.1 Out of scope use/environments
The types of product with digital elements listed in the section do not fall within the scope of the the Regulation (EU) 2024/2847 (Cyber Resilience Act), and are not covered by this standard:
@@ -320,26 +314,66 @@ The following types of products have reduced or varied requirements under Regula
10. Testing and unfinished versions as defined in recital 37; Article 4, 2-3 <aname="_ref_i.1">[i.1]</a>;
11. Products Placed on the Market Prior to December 11, 2027 as defined in CRA article 69 <aname="_ref_i.1">[i.1]</a>.
## 4.3 Product overview and architecture
## 4.2 Product overview and architecture
> Explain the overall architecture and relationship among the parts of the products. Use diagrams if that is helpful.
#### 4.2.1 General
As a holistic product, a Virtual Private Network includes, at mminimum, VPN client or software running in two or more locations which establish a secure encryptd tunnel to communicate. Most typically that involves VPN servers communicating with other VPN servers and/or VPN client software running on one or more endpoints.
### 4.2.2 Architecture

### 4.2.3 VPN server
TK
### 4.2.4 VPN gateway, VPN concentrator
TK
### 4.2.5 VPN client
TK
## 4.4 Use cases
> Create a list of representative use cases, each one representing a different threat profile. If the threat profile is the same for two use cases, then it is basically the same use case for the purposes of the present document. Use cases should include both intended and reasonably foreseeable use/misuse. Use cases don't include industrial operations, automotive, transport, marine, airplane, medical, military, national security, etc.
> When you have many use cases, group them into 3 - 5 levels of risk. These will probably be your security levels.
### 4.4.1 VPN software intended for enterprise workforce deployment
### 4.4.1 Overview
- Systems can range in complexity, including servers, gateways, and concentrators
This list of use cases is an informative resource to the manufacturer to simplify choosing a set of security requirements. Each use case is mapped to a security level, which is a collection of risks and the security requirements necessary to mitigate them.
### 4.4.2 VPN software intended for enterprise workforce deployment
- [TK-A-1] VPN server
- Professionally administration by enterprise IT
- Authenticated access is limited to approved roles
- Physical access is usually limited by data center access
- May include on-prem hardware, software intended for on-prem hardware, or cloud services
- May include client software for data centres or end user devices
- Securely connects two distinct private networks, or an individual user to a remote private network
- [TK-A-2] VPN gateway, VPN concentrator
- Enables site-to-site VPN, combining two or more disparate physical networks as one
- Deployed to high traffic, high complexity environments
- Offers an advanced version of VPN server functionality, with more effective scaling
- May be put on the market on its own dedicated hardware (concentrator)
- [TK-A-3] VPN Client
- Software deployed to endpoints
- Endpoints are typically managed devices
- Software is typically preconfigured, providing limited opportunity for end user error in configuration
- Carries significant risk due to its entrypoint into a private network
### 4.4.2 VPN software connecting data centres
- Systems can range in complexity, potentially including servers, gateways, and concentrators
- [TK-B-1] Site-to-site VPN
- Professionally administration by software developers or operations
- Deployed to cloud data centres or on-prem data centres
- Prioritises high throughput
### 4.4.3 VPN software intended for high-security enterprise