Commit 15d9da35 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Rebase cleanup

parent d2f59508
Loading
Loading
Loading
Loading
+7 −11
Original line number Diff line number Diff line
@@ -159,7 +159,6 @@ The present document applies to Network management systems Products with digital

This category includes but is not limited to end-to-end management systems and dedicated configuration management systems, such as controllers for software-defined networking.

The IP-connection may exclude other means of remote management, such as the management provisioning via Bluetooth which is common for consumer devices. Bluetooth consumer devices are usually not managed by an NMS, however, if they are capable, a NMS management could control them too, as Bluetooth is just a communication media and can be used also for management traffic. Such, NMS’s often control more than just network configuration - e.g., MDM systems.
The IP-connection may exclude other means of remote management, such as the management provisioning via Bluetooth which is common for consumer devices. Bluetooth consumer devices are usually not managed by an NMS, however, if they are capable, a NMS management could control them too, as Bluetooth is just a communication media and can be used also for management traffic. Such, NMS’s often control more than just network configuration - e.g., MDM systems.

## 1.3 Products not in scope
@@ -311,7 +310,6 @@ Manufacturers shall be responsible for implementing all cybersecurity measures,
-   Isolated management system design
-   Pocket deployments with high independency


Devices are limited in functionality like:

1. Simple low-risk embedded device (coffee machine, fridge)
@@ -370,11 +368,11 @@ There can be multple devices in the same network, and the NMS provides supportin

**Figure 4.4.2.1-1: Office network**

#### 4.4.2.3 Telecom network
#### 4.4.2.2 Telecom network

![Figure 4.4.2.3-1: Telecom network](./media/2025-08-10_telco.drawio.png)
![Figure 4.4.2.2-1: Telecom network](./media/2025-08-10_telco.drawio.png)

**Figure 4.4.2.3-1: Telecom network**
**Figure 4.4.2.2-1: Telecom network**

-   Large enterprice network

@@ -429,15 +427,13 @@ If the actual use case cannot be clearly assigned, the manufacturer shall includ
|:-----|:-|:-|:-|:-|
| [4.4.1.1 IoT network with monitoring data collection] | SRU-L-0 | COM-L-0 | EXP-L-0 | ACC-L-1 | ACC-L-2 or ACC-L-3 |
| [4.4.1.2 Home network deployment]                     | SRU-L-0 | COM-L-1 | EXP-L-0 | ACL-L-2 | ACC-L-2 or ACC-L-3 |
| [4.4.2.3 Office network]                              | SRU-L-1 | COM-L-2 | EXP-L-0 | ACL-L-2 | ACC-L-2            |
| [4.4.2.4 Waste management]                            | SRU-L-1 | COM-L-2 | EXP-L-0 | ACL-L-2 | ACC-L-0 or ACC-L-1 |
| [4.4.2.5 Telecom network]                             | SRU-L-2 | COM-L-3 | EXP-L-1 | ACL-L-3 | ACC-L-0 or ACC-L-1 |
| [4.4.2.1 Office network]                              | SRU-L-1 | COM-L-2 | EXP-L-0 | ACL-L-2 | ACC-L-2            |
| [4.4.2.2 Telecom network]                             | SRU-L-2 | COM-L-3 | EXP-L-1 | ACL-L-3 | ACC-L-0 or ACC-L-1 |

[4.4.1.1 IoT network with monitoring data collection]: #4411-iot-network-with-monitoring-data-collection
[4.4.1.2 Home network deployment]: #4412-home-network-deployment
[4.4.2.1 Office network]: #4421-office-network
[4.4.2.2 Waste management]: #4422-waste-management
[4.4.2.3 Telecom network]: #4423-telecom-network
[4.4.2.2 Telecom network]: #4423-telecom-network

## 4.6 Security Profile

@@ -479,7 +475,7 @@ The OE for [SRU-L-2] shall ensure:

Human users of the system are natural persons, trained and qualified at NMS administrators, and authorized to manage the NMS and the connected NEs. Administrators typically access the system through a HTTPS GUI, console, or by VPN connection. 

MMachine users are servers or any other type of a computer that are identified and authenticated by communication protocols that protect the communication between the NMS and the machine user. Once the protected communication has been established, the machine user receives the according authorization by the NMS.
Machine users are servers or any other type of a computer that are identified and authenticated by communication protocols that protect the communication between the NMS and the machine user. Once the protected communication has been established, the machine user receives the according authorization by the NMS.

Service Requesting Users do neither have a direct interface to, nor could they interact or login via other ways to the NMS. Nevertheless, SRUs rely on the correct functioning of the NEs and therewith on the NMS.