Commit 32212a9b authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Planned the structure

parent e60730c4
Loading
Loading
Loading
Loading
+18 −6
Original line number Diff line number Diff line
@@ -396,23 +396,33 @@ Following list of essential functions keep the NMS self-secure and correct funct

## 4.8 Operational Environment

The technical requirements of the present document apply under the environmental profile for operation of the product with digital elements, which shall be in accordance with its intended use. The product with digital elements shall comply with all the technical requirements of the present document at all times when operating within the boundary limits of the operational environmental profile defined by its intended use.
The technical requirements of the present document apply under the environmental profile for operation of the product in accordance with its intended use.

>Distributed element design
>
>Editor's Note: Unclear and to discuss: what is distributed and where? Are elements also outside a defined operational environment? If so then further security requirements apply.
### 4.8.x Applying encryption in OSI-model

>This section should also have the OSI-model and TCP/IP model opened as a reference. Crypto doesn't fit everywhere.

### 4.8.x System isolation

>Isolated management system design
>
>Editor's Note: What is an isolated design? That needs a clarification. Does that mean a generalized serial NMS product, procured as standalone?

When management system is deployed on shared resources, the resource hierarchy, dependencies and control boundaries becomes a points of interest.
### 4.8.x Managed Network Architecture

#### Distributed element design

>Distributed element design
>
>Editor's Note: Unclear and to discuss: what is distributed and where? Are elements also outside a defined operational environment? If so then further security requirements apply.

#### Pocket deployment

>Pocket deployments with high independency
>
>Editor's Note: What is a pocket deployment? That needs a clarification. Does that mean deployment in a from public networks isolated closed network?

>This section should also have the OSI-model and TCP/IP model opened as a reference. Crypto doesn't fit everywhere.
When management system is deployed on shared resources, the resource hierarchy, dependencies and control boundaries becomes a points of interest.

> An old block from !25:

@@ -427,6 +437,8 @@ The OE for [SRU-L-2] shall ensure:
•	Physical access control to ensure access by authorized staff only
•	Authorized staff shall be trained and qualified on the NMS, trusted, operate without malicious intent and act according the NMS user guidelines

### 4.8.x Identifying privileged subjects

> A block from IAM

As necessary functions as identification and authorisation are, a NMS can still serve traffic without perfroming an identification routine as long as that traffic is authorised in another way.