@@ -138,6 +138,10 @@ The following referenced documents may be useful in implementing an ETSI deliver
<spanid="_ref_i.15"></span><aname="_ref_i.15">[i.15]</a> prEN 40000-1-2 "Principles for cyber resilience"
<spanid="_ref_i.16"></span><aname="_ref_i.16">[i.16]</a> Directive (EU) 2022/2555 of the European Parliament and the council and (EU) 2024/2690 European Commission implmenting regulation
<spanid="_ref_i.17"></span><aname="_ref_i.17">[i.17]</a> Example source for DDoS related threat reports https://radar.cloudflare.com/reports
[Mitre ATT&CK]:(https://attack.mitre.org)
@@ -149,7 +153,7 @@ This section provides terms and definitions based on CEN/CLC JTC13 WG09's work o
For the purposes of the present document, the following terms apply:
1.**Operating System (OS):** software product that provides an abstract interface to the underlying hardware and control the execution of software
1.**Operating System (OS):** software product that provides an abstract interface to the underlying hardware and that controls the execution of software
1.**Identity Provider (IDP):** system maintaining identity information
1.**Service Requesting Users (<span name="_term_.SRU">SRU</span>):** users relying on the correct functioning of the network element
1.**user:** person having the credentials to login to the NMS to operate administrative actions to control and maintain the managed element
@@ -178,6 +182,9 @@ For the purposes of the present document, the following abbreviations apply:
`MDM Mobile Device Management`
`IAM Identity and Access Management`
`OCI Open Container Initiative`
`SRU Service Requesting Users`
`PII Personally Identifiable Information`
# 4 Product context
@@ -214,45 +221,51 @@ More about assets in [Annex C.1 Assets](#c1-assets) and [Annex C.2 Data](#c11-da
## 4.5 Risk Factors
To address the risks of an NMS product prior a manufacturer's placing it on the market this standard encourages the manufacturer to threat model and risk profile of the use of the product, including its foreseeable uses, and considering the interplay between:
For each NMS placed on the market, the manufacturer shall develop a threat model and risk profile of the foreseeable use of the NMS, and shall consider the interplay between:
- The complexity of foreseeable uses
- The likelihood of incidents, given the foreseeable uses
- The impact of incidents, given the foreseeable uses
- The complexity of foreseeable use
- The likelihood of an incident, given the foreseeable use
- The impact of an incident, given the foreseeable use
The security profile requirements in clause X reflect use cases and intended deployment of the NMS. Security profiles are based on overall risk of the product, a combination of likelihood and potential impact of incidents. Individual risks are judged using the risk factors described here in Annex D, and determine the degree and type of security needed for specific related security requirements.
Risk factor analysis of all appropriate risk factors can be combined to determine an overall risk of the product and label its risk as low, medium, or high. With this approach, each risk factor provides a description of high or low risk related to a particular aspect of the product and when combined a way to judge its overall security needs.
Each risk factor uses a three tier, low-medium-high risk structure. A set of risk factors is used to determine what requirements apply to the product in the later section [5 Requirements specifications](#5-requirements-specifications).
The risk is combination of likelihood and impact.
Each risk factor has instructions when the product should be evaluated in high or low in the respected categories.
The end result is a three tier low-medium-high evaluation of that given risk factor.
A set of risk factors is used to determine what requirements apply to the product in the later section [5 Requirements specifications](#5-requirements-specifications).
The risk factors identified by the risk assessment in Annex C are grouped into risk categories and assigned unique identifiers below.
The risk factors identified by the risk assessment in Annex C are grouped into risk categories and assigned unique identifiers as defined below.
#### 4.5.1.1 Service requesting users
Number of affected Service Requesting Users [<ahref="#_term_.SRU">SRU</a>]
The number of affected Service Requesting Users [<ahref="#_term_.SRU">SRU</a>]
**Key:** [SRU]<br/>
**Rationale:**Affected user base are a factor when determining risk.
**Rationale:**The affected user base impacts the risk definition.
[SRU]<br/> risk **likelihood** is **low**, where:
- The NMS's managed network has well defined traffic.
- The NMS's managed network has only a small variety of traffic classes, for example: IoT network data collection and software updates.
- The NMS's managed network's SRUs are limited to other devices with well-known communication needs.
- The NMS's managed network's SRUs are other devices with well-known communication needs.
[SRU]<br/> risk **likelihood** is **high**, if:
- The NMS's managed network networtk has arbitrary and poorly defined traffic.
- The NMS's managed network serves human users, each with multiple varied devices such as laptops and mobile phones.
- The NMS's managed network networtk has arbitrary and traffic.
- The NMS's managed network serves human users with possible various devices like laptops and mobile phones.
[SRU]<br/> risk **impact** is **low**, if:
- The NMS's managed network serves single household or a small business, small ammount of SRUs.
@@ -291,10 +304,10 @@ Number of affected Service Requesting Users [<a href="#_term_.SRU">SRU</a>]
#### 4.5.1.3 Security expectations of the deployment context
Expectation is hard to describe as a sum of likelihood and impact. Therefore this risk factor is evaluated directly as perceived by the market the product is made available.
The expectations on security are a sum of deployment, its environment, likelihood and impact. Therefore this risk factor is evaluated directly as perceived by the market the product is made available.
**Key:** [NIS2] </br>
**Rationale:**NIS2 identifies entities that require higher level of protection. The important and essential classifications are combined as the NIS2 does't make additional cybersecurity requirements based on classification. The additional mechanisms are often national level.
**Rationale:**The NIS2 [i.16] identifies entities that require higher level of protection. The important and essential classifications are combined, as the NIS2 provides no product related additional cybersecurity requirements based on the entity classification. Additional security mechanisms can be and are definied on national level.
- The deployment context has other mechanisms that helps to identify and react to the security compromises
@@ -304,11 +317,11 @@ Expectation is hard to describe as a sum of likelihood and impact. Therefore thi
[NIS2] </br> risk level is **medium** if:
- NMS is intended for or foreseaably used to manage networks whose NIS2 status is undefined.
- The NMS product is intended or foreeable used an audience of over a thousand users.
- The NMS managed network element is widely used and often used to store significant amounts of personal or financial data.
- The product serves for a medium-sized enterprise as set by NIS2 Article 2.1 [i.16]
- The managed element is widely used
[NIS2] </br> risk level is **high** if:
-- NMS is intended for or foreseaably used to manage networks whose NIS2 status is as important or essential entities
-The product is targeted to NIS2 important or essential entities.
@@ -410,19 +423,18 @@ The following cybersecurity functionalities can be handled from components outsi
- From external provided updates on secured channels that the product uses to update the managed managed elements and also itself.
-**Identity management systems** that provide mechanisms for identification and authentication. The system can include also the lifecycle management for identity credentials [\[i.2\]](#_ref_i.2)
-**Virtual Private Network** providing access to a physical or virtual established network of managed devices that have strictly controlled access to authorised functions of the product. [\[i.3\]](#_ref_i.3)[\[i.4\]](#_ref_i.4)
-**Provision of cryptographic keys**Public key infrastructure or other key management system for services of key generation, provision, establishment, and for certificate services such as generation, signing, verification, validation or withdrawal. [\[i.6\]](#_ref_i.6)
-**Provision of cryptographic keys**coming from a public key infrastructure or other key management system for services of key generation, provision, establishment, and for certificate services such as generation, signing, verification, validation or withdrawal. [\[i.6\]](#_ref_i.6)
-**Security information and event management systems** that collect data from multiple sources, analyse and correlate that data and present it as actionable information for security-related purposes unless it is considered to be integral part of the product features [\[i.7\]](#_ref_i.7)
-**Physical and virtual network interfaces**
-**Operating systems** Operating systems that act as abstraction layer for the hardware system(s) that host the product and are else not involved in the internal functioning. [\[i.5\]](#_ref_i.5)
-**Physical and virtual network interfaces** on the NMS-host and not used or accessed by users for the operation of the NMS.
-**Operating systems** Operating systems that acting as abstraction layer for the hardware system(s) that host the product and are else not involved in the internal functioning. [\[i.5\]](#_ref_i.5)
-**Managed devices** Managed devices, including those that are managed by the product, such as routers, modems and switches. [\[i.8\]](#_ref_i.8)
-**Antivirus**
Furthermore, it is essential to detail the generation and establishment of the trust relations between the NMS and the essential external services and systems.
### 4.10.2 Security functions provided to other products
The NMS shall provide the reliable availability of the operative network, while keeping control and providing traffic meta data and metrics for the administrator for verification of the correct network operation.
Example: A listed managed element in the NMS can be enriched with traffic meta data. For example, and inconclusive, when and with what performance there was relevant traffic throughput, when/from/to there was a managed element managed traffic overload, received failure reporting or similar.
Example: A listed managed element in the NMS can be enriched with traffic meta data. For example, and inconclusive, when and with what performance there was relevant traffic throughput, when/from/to there was a managed element traffic overload, received failure reporting or similar.
@@ -339,15 +339,24 @@ Likewise it may be appropriate for a critical infrastrtcuture facility to deploy
**Figure 4.6.1.2-1: Home network deployment**
In this use case, the network manangement system controls the user's home network of devices and often acts as a gateway or an access point providing connectivity for the user's home to outside networks, usually public. Access points are devices such as a router, switch, modem, or other wireless or wired device controlled and governed by the NMS and physically deployed to the service requesting users home.
In this use case, a home network device discovers or is being discovered by another devices in the same subnetwork through provided network management functions.
The device can act as a gateway or an access point providing connectivity for the user's home to outside networks, usually public.
Access points are devices such as a router, switch, modem, or other wireless or wired device controlled and governed by the NMS and physically deployed to the service requesting users home.
The device can also make the upstream connection technology transparent to the user. Depending on the available infrastructure in the deployment location, connectivity can be through a variety of alternatives, including a mobile network or fiber optics network.
The device can make the upstream connection technology transparent to the user.
Depending on the available infrastructure in the deployment location, connectivity can be through a variety of alternatives, including a mobile network or fiber optics network.
The NMS in this use case is most often locally installed on the device but may be running on a different device within the same network, or as a remote service, a RDPS.
The NMS in this use case can be locally installed on the device but may be running on a different device within the same network, or is a RDPS.
The devices can actively send metrics to the NMS and can serve multiple devices in the same network. The devices can also provide supporting services like DHCP and DNS caching, but beyond such a minimum they can offer more extensive services such as remote connectivity options like VPN server depending on the product.
Initial secret provisioning takes place during device initialization.
A factory reset clears the existing state and restarts the discovery and provisioning process.
Meterics from the devices and other elements within the home network can be forwarded to the NMS, where the user can percieve these meterics and control the configuration of each networked device. In many deployments actual configuration control and review of metrics collected by ther NMS is achieved with an additional service or alternate piece of software, most often a browser, but sometimes is other ways, such as through a command-line interface.
The devices can actively send metrics to the NMS and can serve multiple devices in the same network.
The devices can provide supporting services like DHCP and DNS caching.
The devices can offer more extensive services including remote connectivity options like VPN.
Meterics from the devices and other elements within the home network can be forwarded to the NMS, where the user can percieve these meterics and control the configuration of each networked device.
In many deployments actual configuration control and review of metrics collected by ther NMS is achieved with an additional service or alternate piece of software, most often a browser, but sometimes is other ways, such as through a command-line interface.