Commit 0b4fa396 authored by Miguel Angel Reina Ortega's avatar Miguel Angel Reina Ortega Committed by Santeri Toikka
Browse files

Format editorials

parent 0cb3c82f
Loading
Loading
Loading
Loading
+334 −330

File changed.

Preview size limit exceeded, changes collapsed.

+161 −157
Original line number Diff line number Diff line
@@ -30,8 +30,9 @@ For the purposes of the present annex:
* RDPS means the remote data processing solution performing or supporting operations relevant to the RDPS-dependent product function;
* _RDPS interface_ means the communication boundary between the product-side endpoint and the RDPS-side endpoint.

![Figure 1: RDPS model for Annex R — scope focused on the product ↔ RDPS boundary](./media/AnnexR_RDPS_model.svg)
**Figure Annex R.2-1: RDPS model for Annex R — scope focused on the product ↔ RDPS boundary**
![Figure Annex R.2-1: RDPS model for Annex R — scope focused on the product ↔ RDPS boundary](./media/AnnexR_RDPS_model.svg)

**Figure Annex R.2-1: RDPS model for Annex R — scope focused on the product ↔ RDPS boundary**

## R.3 Threat Model

@@ -54,6 +55,8 @@ The threat model considers the following assets:
For the purposes of _DA-RDPS-001_, _Table 1_ identifies categories of RDPS interaction content and the security properties that are relevant to them.
For the purposes of _DA-RDPS-001_, _Table 1_ identifies potential categories of RDPS interaction content and indicates the security properties to be considered for each category when determining the applicable Annex R requirement families.

**Table Annex R.3.1-1: Security properties for DA-RDPS-001**

| Content type                                | Data authenticity | Integrity | Confidentiality |
| ------------------------------------------- | ----------------- | --------- | --------------- |
| Commands / requests & Responses / decisions | X                 | X         |                 |
@@ -63,7 +66,6 @@ For the purposes of _DA-RDPS-001_, _Table 1_ identifies potential categories of
| Confidential code or update data            | X                 | X         | X               |
| Personal data                               | X                 | X         |                 |

**Table Annex R-1: Security properties for DA-RDPS-001**

> NOTE: In _Table Annex R.3.1-1_, “data authenticity” refers to the authenticity or trusted origin of the exchanged interaction content. It does not refer to authentication of the RDPS boundary endpoint.

@@ -71,12 +73,12 @@ For the purposes of _DA-RDPS-001_, _Table 1_ identifies potential categories of

For the purposes of _DA-RDPS-002_, _Table 2_ identifies the security property relevant to the RDPS-dependent product function.

**Table Annex R.3.1-2: Security property for DA-RDPS-002**

| Content type                    | Availability |
| ------------------------------- | ------------ |
| RDPS-dependent product function | X            |

**Table Annex R-2: Security property for DA-RDPS-002**

### R.3.2 Threat catalogue

The following threats constitute the baseline threat set considered for the RDPS boundary within the scope of Annex R, covering the RDPS interaction content exchanged across the boundary and the availability of the RDPS-dependent product function.
@@ -115,6 +117,8 @@ Security impact: The RDPS-dependent product function may fail to operate as inte

### R.3.3 Assets to Threats mapping

**Table Annex R.3.3-1: Threats ↔ Assets mapping**

| Threat ID | Threat title                                                                                            | Related asset(s) |
| --------- | ------------------------------------------------------------------------------------------------------- | ---------------- |
| T-RDPS-01 | Loss of data authenticity of interactions across the RDPS boundary                                      | DA-RDPS-001      |
@@ -122,7 +126,6 @@ Security impact: The RDPS-dependent product function may fail to operate as inte
| T-RDPS-03 | Unauthorized disclosure of interactions across the RDPS boundary                                        | DA-RDPS-001      |
| T-RDPS-04 | Unavailability, unacceptable delay, or intolerable degradation of interactions across the RDPS boundary | DA-RDPS-002      |

**Table Annex R-3: Threats ↔ Assets mapping**

## R.4 Security Requirements

@@ -326,6 +329,8 @@ Rationale: This requirement provides stronger protection by requiring resilience

### R.4.5 Threats to Requirements mapping

**Table Annex R.4.5-1: Threats ↔ Requirements mapping**

| Threat ID | Requirement(s) - Local product side | Requirement(s) – RDPS side |
| --------- | ----------------------------------- | -------------------------- |
| T-RDPS-01 | REQ-RDPS-L-AUTH-001                 | REQ-RDPS-R-AUTH-001        |
@@ -341,7 +346,6 @@ Rationale: This requirement provides stronger protection by requiring resilience
| T-RDPS-04 | REQ-RDPS-L-AVAIL-002                | REQ-RDPS-R-AVAIL-002       |
| T-RDPS-04 | REQ-RDPS-L-AVAIL-003                | REQ-RDPS-R-AVAIL-003       |

**Table Annex R-4: Threats ↔ Requirements mapping**

## R.5 Conformity assessment

@@ -1209,6 +1213,8 @@ The table below identifies the CRA Annex I Part I requirements that are directly
The purpose of this mapping is to support manufacturer traceability and to identify directly relevant CRA requirements that are not yet fully covered by the current Annex R draft.
Requirements not covered by Annex R remain addressed by the core part of the standard, insofar as they apply to the product as a whole.

**Table Annex R.6-1: CRA Annex I Part I to Annex R requirements mapping**

| Requirements of Regulation | Clause(s) of the present document                                                                                                                                                                                                          |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Annex I, Part 1, (1)       | REQ-RDPS-L-AUTH-001 to -003, REQ-RDPS-L-INTEG-001 to -003, REQ-RDPS-L-CONF-001 to -003, REQ-RDPS-L-AVAIL-001 to -003, REQ-RDPS-R-AUTH-001 to -003, REQ-RDPS-R-INTEG-001 to -003, REQ-RDPS-R-CONF-001 to -003, REQ-RDPS-R-AVAIL-001 to -003 |
@@ -1226,9 +1232,8 @@ Requirements not covered by Annex R remain addressed by the core part of the sta
| Annex I, Part 1, (2)(l)    | Covered by the requirements in the core part of the standard                                                                                                                                                                               |
| Annex I, Part 1, (2)(m)    | Covered by the requirements in the core part of the standard                                                                                                                                                                               |

**Table Annex R-5: CRA Annex I Part I to Annex R requirements mapping**


**Table Annex R.6-2: CRA Annex I Part I gap analysis**

| Requirements of Regulation | Rationale / gap analysis                                                                                                                                                                                                                                                                                                                   |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
@@ -1247,4 +1252,3 @@ Requirements not covered by Annex R remain addressed by the core part of the sta
| Annex I, Part 1, (2)(l)    | This concerns broader product-level logging, recording, monitoring, and user-facing control requirements.                                                                                                                                                                                                                                  |
| Annex I, Part 1, (2)(m)    | This concerns broader product-level data and settings lifecycle management and is outside the RDPS-boundary interaction focus of Annex R.                                                                                                                                                                                                  |
**Table Annex R-6: CRA Annex I Part I gap analysis**