***CYB_OPS-1** The product shall clearly indicate deployment, update, and upgrade instructions expected from the operational environment (OE).
***CYB_OPS-2** The product shall describe the traffic related to the product operation, including at minimum, configuration, metrics, and API access, that is addressed as Application-level traffic as per RFC 1122 [\[2\]](#_ref_2).
***CYB_OPS-3** The product shall satisfy the applicable remote data processing solutions requirements specified in [Annex R](#annex-r-normative-additional-provisions-for-products-relying-on-remote-data-processing-solutions-rdps).
This requirement applies to the subset of products that rely on a remote data processing solution (RDPS) for the provision or support of one or more product functions.
* This requirement applies to the subset of products that rely on a remote data processing solution (RDPS) for the provision or support of one or more product functions.
> NOTE: [Annex R](#annex-r-normative-additional-provisions-for-products-relying-on-remote-data-processing-solutions-rdps) specifies supplementary requirements for the product-facing RDPS boundary and does not replace the requirements applicable to the product function as such.
@@ -1204,10 +1203,10 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
2. provide a user notification or other informative function when using such methods, and
3. inform the user which component requires the backwards compatible mechanism, and
4. indicate an upgrade path to using more secure cryptography when available.
This requirement applies to the subset of products that provide backward compatibility with cryptographic algorithms other than those listed in [clause K.3](#k.3-acm-extended-cryptographic-mechanisms).
* This requirement applies to the subset of products that provide backward compatibility with cryptographic algorithms other than those listed in [clause K.3](#k.3-acm-extended-cryptographic-mechanisms).
***SBD-TECH-3** The product shall provide a method with which to reset to a secure by default setting.
> NOTE: The CRA essential requirement laid out in Annex 1 Part 1 (2) (b) provides for an applicability exception to the secure configuration by default Essential Cybersecurity Requirement in the scenario that the manufacturer and business user have an agreement in relation to a tailor-made product with digital elements. That exception does not exempt products from the requirement to provide a method to reset to a secure by default configuration.
## 5.5 Security updates
@@ -1221,21 +1220,17 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
***SU_UPDATES-5:** The product shall maintain a monotonic version counter or equivalent mechanism to prevent installation of updates with an older version.
***SU_UPDATES-6:** The product shall provide a mechanism to restore the system to the operational state after a failed update.
***SU_UPDATES-7:** The product shall provide a way for the system user to postpone or re-schedule the application update.
This requirement applies to the subset of products within the indicated use cases that operate in an operational environment that allows for postponement or rescheduling of application updates.
* This requirement applies to the subset of products within the indicated use cases that operate in an operational environment that allows for postponement or rescheduling of application updates.
***SU_UPDATES-8:** The product shall require explicit authorization and emit an auditable event containing metadata when intentaional rollback is invoked.
This requirement applies to products that support intentional version rollback.
* This requirement applies to products that support intentional version rollback.
***SU_UPDATES-9:** The product shall automatically recover from a failed update and resume operation if applicable or otherwise achieve a secure state.
***SU_UPDATES-10:** The product shall inform the system user about update availability if applicable.
***SU_UPDATES-11:** The product shall track the relevant component versions of the product and the managed elements if applicable.
***SU_UPDATES-12:** The product shall log start and finish of the update download if applicable.
***SU_UPDATES-13:** The product shall perform an automatic update of the product and the managed elements.
This requirement applies to products that support automatic updates without impacting the defined availability targets.
* This requirement applies to products that support automatic updates without impacting the defined availability targets.
***SU_UPDATES-14:** The product shall enable automatic updates by default.
This requirement applies to products that support automatic updates without impacting the defined availability targets.
* This requirement applies to products that support automatic updates without impacting the defined availability targets.
## 5.6 Authentication and access control
@@ -1296,16 +1291,16 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
***CON_INGEST-1** The product shall protect the confidentially and integrity of the collected network element monitoring data.
***CON_INGEST-2** The product shall cryptographically protect relevant data at rest and in transit, including at minimum:
* secrets
* confidential configuration data
* metrics that can expose confidential data
1. secrets
2. confidential configuration data
3. metrics that can expose confidential data
***CON_INGEST-3** The product shall provide measures appropriate to product use to protect the integrity and, where required, the confidentiality of data relevant to monitoring, control, or security functions that is transferred over connections not controlled by the product.
***CON_CRYPTO-1** To prevent rollback or downgrade [i.17] the product shall:
* enforce a monotonic cipher suite policy configuration (or equivalent mechanism);
* preven the re-enabling of deprecated algorithms or the disabling of security checks via a rollback operation without having an explicit logged administrative override in place.
1. enforce a monotonic cipher suite policy configuration (or equivalent mechanism);
2. preven the re-enabling of deprecated algorithms or the disabling of security checks via a rollback operation without having an explicit logged administrative override in place.
### 5.7.2 Secure channel
@@ -1321,10 +1316,11 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
### 5.8.1 Configuration integrity
***INT_CONF-2** The product shall ensure that:
* product configuration is protected against unauthorized modification and disclosure, and
* only the intended managed element can obtain the relevant configuration, and
* the device can verify the integrity of the configuration.
This requirement applies products that distribute or make available configuration to managed elements.
1. product configuration is protected against unauthorized modification and disclosure, and
2. only the intended managed element can obtain the relevant configuration, and
3. the device can verify the integrity of the configuration.
* This requirement applies products that distribute or make available configuration to managed elements.
***INT_CONF-3** The configuration interfacing design shall enable the managed element to cryptographically verify the authenticity of the product.
### 5.8.2 Cryptographic key initialisation and rotation
@@ -1340,18 +1336,18 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (g).
***DM_RETENTION-1** The product shall define what is logged, and how long that record is kept by default, in group level accuracy.
***DM_RETENTION-2** The product shall define which metrics are gathered, and how long those records are kept by describing, at minimum:
1. metric name
2. metric description
3. metric cadence, if relevant for the collected metric
4. default storage time
***DM_RETENTION-3** The product shall not collect data unrelated to the purpose of the product operation.
> EXAMPLE: group-level accuracy may resemble
> * application debug output
> * application output labeled warning or critical
> * privilege escalations in the application operation
> * network configuration changes
***DM_RETENTION-2** The product shall define which metrics are gathered, and how long those records are kept by describing, at minimum:
* metric name
* metric description
* metric cadence, if relevant for the collected metric
* default storage time
***DM_RETENTION-3** The product shall not collect data unrelated to the purpose of the product operation.
## 5.10 Availability protection
@@ -1367,24 +1363,21 @@ For **low** risk:
For **medium** risk:
***AP_HA-3** The product shall tolerate loss of resources within the limits of the defined availability.
[//]:#(TODO this belongs in 5.11)
***AP_HA-4** The product shall minimise the impact to other systems when anomalies occur.
For **high** risk:
***AP_HA-5** The product shall implement coordinated brute‑force and overload protection mechanisms that not only detect excessive authentication attempts or inbound traffic surges, but also enforce active mitigation actions, including at minimum
* temporary IP blocking, and
* message buffering, and
* QoS parameterisation.
1. temporary IP blocking, and
2. message buffering, and
3. QoS parameterisation.
***AP_HA-6** The product shall implement recovery or failover mechanisms.
***AP_HA-7** The product shall implement DDoS mitigations including at minimum:
* port switching
* traffic redirections
* service termination for a recommended and configurable time
* disabling of the affected ports and interfaces for a configurable time
This requirement applies to products which can be exposed to DDoS.
1. port switching
2. traffic redirections
3. service termination for a recommended and configurable time
4. disabling of the affected ports and interfaces for a configurable time
* This requirement applies to products which can be exposed to DDoS.
## 5.11 Non-interference
@@ -1450,40 +1443,36 @@ For **low** risk:
***MON_LOG-2** The product shall protect log data of events from modification including their deletion, execpt if the modification relates to an execution of planned rotation policy in the product.
***MON_LOG-3** The product shall protect the confidentiality of events within log data.
***MON_LOG-4** The product shall include, at minimum, the following fields in a machine-readable format in its log data:
* event timestamp,
* actor identity,
* action type,
* affected non-sensitive scope, and
* object identifiers.
1. event timestamp,
2. actor identity,
3. action type,
4. affected non-sensitive scope, and
5. object identifiers.
***MON_LOG-5** The product shall log all received relevant events from its managed elements in a machine readable format including, at minimum:
* incidents
* alarms
* time shift alarms.
The following requirements apply where the corresponding function exists:
1. incidents
2. alarms
3. time shift alarms.
***MON_LOG-6** The product shall generate auditable events including, at minimum:
* successful and failed authentication events
* session establishment attempts with source details
* session termination events with a reason
* session validation checks like number of concurrent sessions
* privilege and role changes
* configuration changes
* device enrollment and unenrollment
* trust-anchor changes
* policy changes
* credential changes
* events described by [5.5 Security updates](#55-security-updates)
* installation successes and failures in the managed elements, if that information can be extracted from the targets
* installation successes and failures in the product itself.
This requirement applies to the subset of products that support the corresponding function for each item.
1. successful and failed authentication events
2. session establishment attempts with source details
3. session termination events with a reason
4. session validation checks like number of concurrent sessions
5. privilege and role changes
6. configuration changes
7. device enrollment and unenrollment
8. trust-anchor changes
9. policy changes
10. credential changes
11. events described by [5.5 Security updates](#55-security-updates)
12. installation successes and failures in the managed elements, if that information can be extracted from the targets
13. installation successes and failures in the product itself.
* This requirement applies to the subset of products that support the corresponding function for each item.
***MON_LOG-7** The product shall log boot or initialisation events including at minimum:
* timestamped boot stage progression,
* software component verification and initialisation actions, and
* recovery mode activations if in use.
This requirement applies to the subset of products that support the corresponding function for each item.
1. timestamped boot stage progression,
2. software component verification and initialisation actions, and
3. recovery mode activations if in use.
* This requirement applies to the subset of products that support the corresponding function for each item.
> NOTE: **MON_LOG-7** Writing a log record in case of an error during the booting process might not be possible in all cases, as the product is not completely functional when the booting process has not successfully completed. The event recording function is made available during the booting process.
@@ -1497,16 +1486,16 @@ For **high** risk:
***MON_LOG-10** The product shall support forwarding of relevant administrative events to an external logging or SIEM system.
***MON_LOG-11** The product shall produce logs, SIEM event data transfer format, field attributes and event descriptions in a machine readable format.
***MON_LOG-12** The product shall export logs as data artifacts that preserve essential fields, at minimum:
* timestamp when the event occurred
* actor
* action type
* affected scope
* result.
1. timestamp when the event occurred
2. actor
3. action type
4. affected scope
5. result.
***MON_LOG-13** The product shall record sufficient provenance information to attribute a change to an actor and context information related to, at minimum:
* authoritative subject
* automated workflow if relevant for the event context
* policy or rule identifier
* and triggering event reference.
1. authoritative subject
2. automated workflow if relevant for the event context
3. policy or rule identifier
4. and triggering event reference.
> NOTE: **MON_LOG-13** describes privilege escalations that are done in computation. A common tactic to infiltrate a system is to trick it to escalate attacker access rights.
@@ -1532,12 +1521,11 @@ For **high** risk:
2. provided services
3. the system itself.
## 5.15 Factory reset and data portability
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (m).
Due to complexity, and industry wide use of various protocols and best practices, the support for data transfer is not required.
> NOTE: Due to complexity, and industry wide use of various protocols and best practices, the support for data transfer is not required.
***DRT_DELETE-1** The product shall:
1. provide a function to remove all data and settings, or