@@ -1547,7 +1547,7 @@ This document assumes that those devices will get compromised.
For **low** risk:
***EMM_ROUTE-1** The connection to the managed element shall be configurable to enforce granular packet filtering by managed element or server identity, and destination address.
***EMM_ROUTE-1** The product shall be configurable to enforce granular packet filtering by managed element or server identity, and destination address when creating a connection to a managed element.
For **medium** risk:
@@ -1600,29 +1600,33 @@ The following requirements apply where the corresponding function exists:
* events described by [5.5 Security updates](#55-security-updates)
* installation successes and failures in the managed elements, if that information can be extracted from the targets
* installation successes and failures in the product itself.
This requirement applies to the subset of products that support the corresponding function for each item.
***MON_LOG-7** The product shall log boot or initialisation events including at minimum:
* timestamped boot stage progression
* software component verification and initialisation actions
* timestamped boot stage progression,
* software component verification and initialisation actions, and
* recovery mode activations if in use.
This requirement applies to the subset of products that support the corresponding function for each item.
> NOTE: **MON_LOG-7** Writing a log record in case of an error during the booting process might not be possible in all cases, as the product is not completely functional when the booting process has not successfully completed. The event recording function is made available during the booting process.
For **medium** risk:
***MON_LOG-8:** The log information shall have an active backup scheduled.
***MON_LOG-9:** The audit logs shall be tamper-evident.
***MON_LOG-8:** The product shall actively schedule backups for log information.
***MON_LOG-9:** The product shall maintain tamper-evident audit logs.
For **high** risk:
***MON_LOG-10** The product shall support forwarding of relevant administrative events to an external logging or SIEM system.
***MON_LOG-11**Logging or SIEM event data transfer format, field attributes and event descriptions shall be made available in a machine readable format.
***MON_LOG-12**Exported log data artifacts shall preserve essential fields at least, at minimum:
***MON_LOG-11**The product shall produce logs, SIEM event data transfer format, field attributes and event descriptions in a machine readable format.
***MON_LOG-12**The product shall export logs as data artifacts that preserve essential fields, at minimum:
* timestamp when the event occurred
* actor
* action type
* affected scope
* result.
***MON_LOG-13** The product shall record sufficient provenance information to attribute a change to an actor and context information related to at least, at minimum:
***MON_LOG-13** The product shall record sufficient provenance information to attribute a change to an actor and context information related to, at minimum:
* authoritative subject
* automated workflow if relevant for the event context
* policy or rule identifier
@@ -1636,15 +1640,15 @@ The metrics requirements in this subclause support security monitoring, operatio
Fulfilment of these requirements is essential for all products in all use cases and all risk levels.
Breaches can not be detected, if an attacker can hide its existence.
***MON_METRICS-1** The product shall be designed in a way that collected and stored metrics data can not be altered.
***MON_METRICS-2** The import of previously recorded metric data that overwrite an already present data point shall be noticed.
***MON_METRICS-3**Metrics name, purpose, and value interpretation shall be described for the product user.
***MON_METRICS-1** The product shall prevent alteration of collected and stored metrics data.
***MON_METRICS-2** The product shall dispatch an event noting the import of previously recorded metric data if that data will overwrite existing data.
***MON_METRICS-3**The product shall record metrics name, purpose, and value interpretation shall in a manner accessible to the product user.
> NOTE: **MON_METRICS-3** leaves open how the information is conveyed to the product user. It could be a dedicated portal within the product or machine readable output having the same information.
A number of metrics depend on the operational environment or used protocols and are applicable as follows:
***MON_METRICS-4** The product shall collect, track and store metrics on, including, at minimum:
***MON_METRICS-4** The product shall collect, track, and store metrics on, at minimum:
1. availability and status changes, like process and service crashes and restarts
2. incidents, warning and notification events reported by the target
3. relevant operative information like CPU, memory, disk utilisation
@@ -1672,7 +1676,9 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
Due to complexity, and industry wide use of various protocols and best practices, the support for data transfer is not required.
***DRT_DELETE-1** The product shall provide a function to remove all data and settings or support full re-install to restore to its secure-by-default state.
***DRT_DELETE-1** The product shall:
1. provide a function to remove all data and settings, or
2. support full re-installation to restore to its secure-by-default state.
***DRT_DELETE-2** If import and export of data is available, the related data transfer shall use a secure channel.
# 6 Assessment criteria for compliance with technical requirements