Commit 0bf484d6 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Added risk distribution

parent de6a8260
Loading
Loading
Loading
Loading
+20 −10
Original line number Diff line number Diff line
@@ -11,11 +11,7 @@
<br />
<br />

Title;<br />

Part #: Part element of title;<br />

Sub-part #: Sub-part element of title<br />
CRA; Essential cybersecurity requirements for network management systems<br />

Release #<br />

@@ -205,12 +201,13 @@ References are either specific (identified by date of publication and/or edition

The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's understanding but are not required for conformance to the present document.

- <a name="_ref_i.1">[i.1]</a> Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)

- <a name="_ref_i.1">[i.1]</a> EU 2024/2847 "Cyber Resilience Act" 
- <a name="_ref_i.2">[i.2]</a> ETSI hEN IAM
- <a name="_ref_i.3">[i.3]</a> ETSI hEN OS
- <a name="_ref_i.4">[i.4]</a> ETSI hEN PKI
- <a name="_ref_i.4">[i.5]</a> ETSI hEN SIEM
- <a name="_ref_i.3">[i.3]</a> ETSI EN 304 620 "VPN"
- <a name="_ref_i.4">[i.4]</a> CEN/CLC EN 50XXX-4 "VPN"
- <a name="_ref_i.5">[i.5]</a> ETSI EN 304 626 "Essential cybersecurity requirements for operating systems"
- <a name="_ref_i.6">[i.6]</a> ETSI hEN PKI
- <a name="_ref_i.7">[i.7]</a> ETSI hEN SIEM

# 3 Definition of terms, symbols and abbreviations

@@ -436,6 +433,19 @@ The technical requirements of the present document apply under the environmental

> Describe what risks are delegated to other components, as well as what security functionalities this product offers to things integrated with it.

The following security functionalities are handled by other systems:

* Secure update of firmware and/or device driver
* **Identity management systems** that provide mechanisms for authentication or authorisation and that may also provide mechanisms for the lifecycle management of identity credentials
* **Virtual Private Network** that provide access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network
* **Security information and event management systems** that collect data from multiple sources, analyse and correlate that data and present it as actionable information for security-related purposes unless it is considered to be integral part of the NMS product features
* **Physical and virtual network interfaces**
* **Operating systems** that provide an abstract interface of the underlying hardware and control the execution of software
* **Routers, modems and switches** that establish and control the flow of data between different networks

<mark> Should this be in: * Provision of cryptographic keys? Is a generic NMS provisioning cryptographic keys to the managed devices?</mark>


## 4.10 Support period

> Describe the expected support period and its impact on security risks. Generally the support period should be at least 5 years, shorter or longer according to the expected period of use. See Article 13.8 and Recitals 59 - 62 of the CRA for more information.