Commit 0774d666 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Updated 5.1 Intro

parent 78fb11e6
Loading
Loading
Loading
Loading
+17 −16
Original line number Diff line number Diff line
@@ -1038,39 +1038,42 @@ The technical documentation referenced in this clause is intended to describe th

The technical requirements of the present document apply under the product context described in Clause 4, which shall be in accordance with its intended use. The product shall comply with all applicable technical requirements of the present document at all times when operating in such a product context.

Not all requirements are universally applicable: The applicability of requirements may be based on use cases or specific capabilities of the product.
The requirements in this section are unconditionally applicable, unless specifically indicated with a conditional phrasing.

When requirements are divided into low-medium-high categories, the categories are cumulative.
Medium requirement level shall implement also requirments listed in low level.
High requirement level shall implement all requirements in the defined set of requirements.

<mark>Editor’s Note: Each technical requirement should contain an applicability subclause as short as it might be. Example of the content of such an applicability subclause: “unconditionally applicable”, “applicable to UC-1 and UC-3”, “applicable if the product presents capability X,” “applicable to products of type X (subcategory of product category)”. Applicability subclauses may have compound criteria.</mark>

<mark>Editor’s Note: The applicability subclause should NOT contain generic statements, such as “Applicability based on the manufacturer’s risk assessment”. The legacy nature of products is also not a valid condition to exempt a product from a technical requirement. Applicability should be based on use cases and/or specific capabilities.</mark>

<mark>Editor's Note: If there is a matrix mapping the use cases to the technical requirements of the standard, it should be inserted in this clause. Alternatively, there can be such a matrix/mapping in each subclause below.</mark>

| Use-case      | Requirement set | required level |
| :------------ | :-------------- | -------------- |
| :------------ | --------------- | -------------- |
|               | CYB_GENERAL     | low            |
|               | CYB_GENERAL     | medium         |
|               | CYB_GENERAL     | high           |
| all           | CYB_OPS         | all            |
| all           | KEV_EXPLOIT     | all            |
| all           | SBD_TECH        | all            |
| all           | SU_UPDATE       | all            |
| all           | AAC_AUTH        | all            |
| all           | AAC_MACHINE     | all            |
| all           | CON_INGEST      | all            |
| all           | CON_CRYPTO      | all            |
| all           | CON_CHANNEL     | all            |
| all           | INT_CONF        | all            |
| all           | INT_ROTATE      | all            |
| all           | DM_RETENTION    | all            |
|               | AP_HA           | low            |
|               | AP_HA           | medium         |
|               | AP_HA           | high           |
| UC_HOME       | IM_SEGMENT      | low            |
| UC_ENTERRPISE | IM_SEGMENT      | medium         |
| UC_TELCO      | IM_SEGMENT      | high           |
| all           | MAS_TECH        | all            |
| all           | MON_LOG         | low            |
| all           | MON_LOG         | medium         |
| all           | MON_LOG         | high           |
| all           | EM_             | all            |
|               | MON_LOG         | low            |
|               | MON_LOG         | medium         |
|               | MON_LOG         | high           |
| all           | MON_METRICS     | all            |
| all           | RST_            | all            |

## 5.2 Appropriate level of cybersecurity

@@ -1532,7 +1535,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P

## 5.13 Exploit mitigation

<mark>_Proposed ESR code: EMM_</mark>
<mark>_Proposed ESR code: EM_</mark>

This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (k).

@@ -1547,7 +1550,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
In many product deployments, privileged users manage monitoring tasks also with the analysis of product logging records.
Especially when there are forensic demands, comprehensive and detailed logging becomes a larger challenge.

The logging requirements in this subclause define baseline event recording and additional protections for retention, integrity, backup, and external forwarding according to the applicable risk tier.
The logging requirements in this subclause define baseline event recording and additional protections for retention, integrity, backup, and external forwarding.

For **low** risk:

@@ -1615,8 +1618,6 @@ The metrics requirements in this subclause support security monitoring, operatio
Fulfilment of these requirements is essential for all products in all use cases and all risk levels.
Breaches can not be detected, if an attacker can hide it's existense.

General requirements that are unconditionally applicable:

* **MON_METRICS-1** The product shall be designed in a way that collected and stored metrics data can not be altered.
* **MON_METRICS-2** Historical metrics data import overwriting an existing data point shall be noticed.
* **MON_METRICS-3** Metrics name, purpose, and value interpretation shall be described for the product user.
@@ -1649,7 +1650,7 @@ What metrics and logs can be collected is defined in more detail in [5.9 Data mi

## 5.15 Factory reset and data portability

<mark>_Proposed ESR code: DRT_</mark>
<mark>_Proposed ESR code: RST_</mark>

This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (m).