Verified Commit 3c39beba authored by Aki Braun's avatar Aki Braun
Browse files

Editoial: "but not limited to" -> "at minimum"

parent bca62755
Loading
Loading
Loading
Loading
+11 −11
Original line number Diff line number Diff line
@@ -1168,7 +1168,7 @@ For **high** risk:
### 5.2.3 Operative environment

* **CYB_OPS-1** The product shall clearly indicate deployment, update, and upgrade instructions expected from the operational environment (OE).
* **CYB_OPS-2** The product shall describe the traffic related to the product operation, including but not limited to configuration, metrics and API access, that is addressed as Application-level traffic as per RFC 1122 [\[2\]](#_ref_2).
* **CYB_OPS-2** The product shall describe the traffic related to the product operation, including at minimum, configuration, metrics, and API access, that is addressed as Application-level traffic as per RFC 1122 [\[2\]](#_ref_2).
* **CYB_OPS-3** The product shall satisfy the applicable remote data processing solutions requirements specified in [Annex R](#annex-r-normative-additional-provisions-for-products-relying-on-remote-data-processing-solutions-rdps).

  This requirement applies to the subset of products that rely on a remote data processing solution (RDPS) for the provision or support of one or more product functions.
@@ -1310,7 +1310,7 @@ These requirements apply to the product, regardless of the product's use case an
    * software state
    * availability
    * network reachability.
* **AAC_AUTH-10** The product's authorisation decision shall be bound to, and made available in, auditable event data, including but not limited to:
* **AAC_AUTH-10** The product's authorisation decision shall be bound to, and made available in, auditable event data, including at minimum:
    * source of the identity
    * the acting identity
    * whether natural user or machine user
@@ -1534,8 +1534,8 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P

* **MAS_TECH-1** The product shall:
  1. document all communication interfaces, and
  2. not expose any interfaces or initiate connections other than those documented, and
  3. interfaces not required for the intended use shall be disabled by default.
  2. refrain from exposing any interfaces or initiating connections other than those documented, and
  3. disable by default interfaces not required for the intended use.
* **MAS_TECH-2** The product shall not connect to undocumented RDPS services.

## 5.13 Exploit mitigation
@@ -1573,20 +1573,20 @@ For **low** risk:
* **MON_LOG-1** The log data of events shall be protected from unauthorised access.
* **MON_LOG-2** The log data of events shall be protected from modification including their deletion, execpt if the modification relates to an execution of planned rotation policy in the product.
* **MON_LOG-3** The log data of events shall be confidentiality protected.
* **MON_LOG-4** The log information shall include the following fields in a machine readable format including, but not limited to:
* **MON_LOG-4** The log information shall include the following fields in a machine readable format including, at minimum:
    * event timestamp
    * actor identity
    * action type
    * affected non-sensitive scope
    * and object identifiers.
* **MON_LOG-5** The product shall log all received relevant events from its managed elements in a machine readable format including, but not limited to:
* **MON_LOG-5** The product shall log all received relevant events from its managed elements in a machine readable format including, at minimum:
    * incidents
    * alarms
    * time shift alarms.

The following requirements apply where the corresponding function exists:

* **MON_LOG-6** The product shall generate auditable events including, but not limited to:
* **MON_LOG-6** The product shall generate auditable events including, at minimum:
    * successful and failed authentication events
    * session establishment attempts with source details
    * session termination events with a reason
@@ -1600,7 +1600,7 @@ The following requirements apply where the corresponding function exists:
    * events described by [5.5 Security updates](#55-security-updates)
    * installation successes and failures in the managed elements, if that information can be extracted from the targets
    * installation successes and failures in the product itself.
* **MON_LOG-7** The product shall log boot or initialisation events including but not limited to:
* **MON_LOG-7** The product shall log boot or initialisation events including at minimum:
    * timestamped boot stage progression
    * software component verification and initialisation actions
    * recovery mode activations if in use.
@@ -1616,13 +1616,13 @@ For **high** risk:

* **MON_LOG-10** The product shall support forwarding of relevant administrative events to an external logging or SIEM system.
* **MON_LOG-11** Logging or SIEM event data transfer format, field attributes and event descriptions shall be made available in a machine readable format.
* **MON_LOG-12** Exported log data artifacts shall preserve essential fields at least, but not limited to:
* **MON_LOG-12** Exported log data artifacts shall preserve essential fields at least, at minimum:
    * timestamp when the event occurred
    * actor
    * action type
    * affected scope
    * result.
* **MON_LOG-13** The product shall record sufficient provenance information to attribute a change to an actor and context information related to at least, but not limited to:
* **MON_LOG-13** The product shall record sufficient provenance information to attribute a change to an actor and context information related to at least, at minimum:
    * authoritative subject
    * automated workflow if relevant for the event context
    * policy or rule identifier
@@ -1644,7 +1644,7 @@ Breaches can not be detected, if an attacker can hide its existence.

A number of metrics depend on the operational environment or used protocols and are applicable as follows:

* **MON_METRICS-4** The product shall collect, track and store metrics on, including, but not limited to:
* **MON_METRICS-4** The product shall collect, track and store metrics on, including, at minimum:
    1. availability and status changes, like process and service crashes and restarts
    2. incidents, warning and notification events reported by the target
    3. relevant operative information like CPU, memory, disk utilisation