Commit 4f66e7bb authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Dropped NE in favor of managed element word

parent 19bc4221
Loading
Loading
Loading
Loading
+33 −8
Original line number Diff line number Diff line
@@ -152,9 +152,9 @@ Network management systems (“NMS”) have been identified as “important prod

## 1.2 Products in scope

The implementing regulation <a href="#_ref_i.11">[i.11]</a> defines in section (2) that the core functionality of a product defines what category it should be evaluated under. The regulation continues to define in section (3), that when the product is a composite of other recognized products, the composite product doesn't inherit all other regulations, but is evaluated only in it's own category.
The implementing regulation <a href="#_ref_i.11">[i.11]</a> defines in section (2) that the core functionality of a product defines what category it should be evaluated under. The regulation continues to define in section (3), that when the product is a composite of other recognised products, the composite product doesn't inherit all other regulations, but is evaluated only in it's own category.

The NMS is defined in the implmenting regulation <a href="#_ref_i.11">[i.11]</a> in Annex I, Class I (6) and is not restricted to only systems that are IP connected. The scope covers all connected elements in the network, that are somehow managed. This includes, but is not limited to, Mobilde Device Managent systems and Software Defined Networking.
The NMS is defined in the implmeneting regulation <a href="#_ref_i.11">[i.11]</a> in Annex I, Class I (6) and is not restricted to only systems that are IP connected. The scope covers all connected elements in the network, that are somehow managed. This includes, but is not limited to, Mobile Device Management systems and Software Defined Networking.

Bluetooth consumer devices are usually not managed by an NMS, however, if they are capable, a NMS management could control them too, as Bluetooth is just a communication media and can be used also for management traffic. Such, NMS’s often control more than just network configuration - e.g., MDM systems.

@@ -218,7 +218,7 @@ For the purposes of the present document, the following terms apply:
1. **Operating System (OS):** software product that provides an abstract interface to the underlying hardware and control the execution of software
1. **Identity Provider (IDP):** system maintaining identity information
1. **Service Requesting Users (<span name="_term_.SRU">SRU</span>):** users relying on the correct functioning of the network element
1. **user:** person having the credentials to login to the NMS to operate administrative actions to control and maintain the NE
1. **user:** person having the credentials to login to the NMS to operate administrative actions to control and maintain the managed element
1. **machine user:** virtual user used to access the system programming interfaces
1. **component:** software or hardware intended for integration into an electronic information system
1. **Application Programming Interface (API):** interface used to communicate with the running program
@@ -276,7 +276,7 @@ The following are products and features that are covered by separate standards:

## 4.3 Product overview and architecture

Network management systems are often deployed <mark>in a star pattern, where all command and control functionality is focused on a centralized set of services, that are providing all required functionality</mark>.
Network management systems are often deployed <mark>in a star pattern, where all command and control functionality is focused on a centralised set of services, that are providing all required functionality</mark>.

Depending on the connected element design and degree of autonomy, the element can often operate fully without constant connectivity to an NMS. In larger network deployments and without adjustments in routing or other operation parameters, the connectivity to the NMS can erode over time.

@@ -942,9 +942,34 @@ There are three different types of assesments used in this document.
## 6.1 General requirements assesments


### 6.1.0.0 REQ-GENERAL-2
### 6.1.0.0 REQ-GENERAL-0

**Requirement REQ-GEN-0:** The product shall have technical documentation with what [Risk factors](#45-risk-factors) the product with digital elements shall be evaluated.<br/>
**Objective:** Prevent exploitation of known exploited vulnerabilities<br/>
**Preparation:**

1. Examine public or private vulnerability information sources and select a recently fixed vulnerability (preferably the most recently fixed).

**Activities:**

1. On a new product, carry out the initial secure update, scan the product to see if a recently fixed vulnerability has been fixed on the product, and examine the documentation for the required info.

**Verdict:**

1. Pass if the secure update completes successfully
1. and the most recently fixed vulnerability is fixed
1. and the documentation includes all the required information
1. and the instructions are noting the custom requirements of the application, if any.
1. Fail otherwise.

**Supporting Evidence:**

1. Documentation of vulnerability handling
1. Documentation of how to securely update the product
1. The report for the selected vulnerability
1. Description of how to scan for the vulnerability
1. Log of vulnerability scan results

-   **[REQ-GEN-0]:** The product shall have technical documentation with what [Risk factors](#45-risk-factors) the product with digital elements shall be evaluated.

### 6.1.0.1 REQ-GENERAL-2

@@ -1100,7 +1125,7 @@ There are three different types of assesments used in this document.
**Verdict:**

1. Pass if provided SBOM identifiers are unique
1. and recognized in the industry
1. and recognised in the industry
1. and cross referable to known vulnerability databases.
1. Fail otherwise.

@@ -1160,7 +1185,7 @@ There are three different types of assesments used in this document.

1. Pass if there are no uknown metrics displayed or collected.
1. Pass if the metric well-known, like CPU usage, but undocumented.
1. Pass if the metric is recognized and pointer to the documentation is provided (managed element manufacturer's reference documentation e.g.).
1. Pass if the metric is recognised and pointer to the documentation is provided (managed element manufacturer's reference documentation e.g.).
1. Fail otherwise.

**Supporting Evidence:**