@@ -138,8 +138,6 @@ The following referenced documents may be useful in implementing an ETSI deliver
<mark>Below this line are reference, that needs to be checked, if needed still.</mark>
<spanid="_ref_i.8"></span><aname="_ref_i_x">[i.8]</a> ENISA April 2025 (Version 2.0) "Agreed Cryptographic Mechanisms"
<spanid="_ref_i.2"></span><aname="_ref_i.2">[i.2]</a> ETSI EN 304 XXX IAM (CEN/TC 224 WG 17 output)
<spanid="_ref_i.3"></span><aname="_ref_i.3">[i.3]</a> ETSI EN 304 620 "Virtual Private Networks (VPNs)"
@@ -191,9 +189,7 @@ For the purposes of the present document, the terms given in Regulation (EU) 202
12.**cryptographic property**: property provided or supported by a cryptographic mechanism
13.**cryptographic mechanism**: security-related procedure using cryptography
This section provides terms and definitions based on CEN/CLC JTC13 WG09's work on terms and definitions provided by ETSI EN 303 645/TS 103 701 and terms and definitions provided by CEN/CLC EN 18031 series.
For the purposes of the present document, the following terms apply:
## 3.2 Symbols
@@ -1078,7 +1074,7 @@ The technical documentation referenced in this clause is intended to describe th
The technical requirements of the present document apply under the product context described in Clause 4, which shall be in accordance with its intended use. The product shall comply with all applicable technical requirements of the present document at all times when operating in such a product context.
The requirements in this section are unconditionally applicable, unless specifically indicated with a conditional phrasing.
The requirements in this section are unconditionally applicable, unless specifically indicated with a conditional phrasing, or the funcionality is implmented with RDPS.
When requirements are divided into low-medium-high categories, the categories are cumulative.
Medium requirement level shall implement also requirements listed in low level.
@@ -1696,7 +1692,7 @@ The assessment needs thereby to be functional complete and sufficient:
## 6.1 Introduction to the assessment and compliance criteria
This clause provides objective and reproducible assessment criteria to determine whether a product complies with the technical security requirements of clause 5.
For each cybersecurity requirement defined in clause 5, the following clauses specify assessment criteria to determine if the technical requirement is met.
For each cybersecurity requirements defined in clause 5, the following clauses specify assessment criteria to determine if the technical requirement is met.
## 6.2 Appropriate level of cybersecurity
@@ -4068,6 +4064,9 @@ Other Union legislation may be applicable to the product(s) falling within the s
# Annex B (informative): Security analysis
This Annex applies state of the art methodology to identify assets, threats, identify and evaluate risk factors, and define security profiles applicable to the different use cases identified in the product context.
For each network management system placed on the market, this annex provides the grounds to develop a threat model and risk profile of the foreseeable use of the system that considers the interplay between:
* Likelihood of an incident, given the foreseeable use