Commit 52a0ec4e authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Review changes from the meeting to requirements

Closes #522, #511
parent 0a760e25
Loading
Loading
Loading
Loading
+2 −2
Original line number Diff line number Diff line
@@ -1295,7 +1295,7 @@ These requirements apply to the product, regardless of the product's use case an
    * privileged function use
    * data access and deletions
    * data changes and permission changes.
* **AAC_AUTH-9** The product shall verify successfully an explicit authorisation decision immediately before execution of any privileged action that can modify, including but not limited to:
* **AAC_AUTH-9** The product shall explicit authorise any privileged action before its execution can modify, including but not limited to:
    * managed-element configuration
    * control-plane behaviour routing or forwarding state
    * security policy
@@ -1659,7 +1659,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
Due to complexity, and industry wide use of various protocols and best practices, the support for data transfer is not required.

* **DRT_DELETE-1** The product shall provide a function to remove all data and settings or support full re-install to restore to its secure-by-default state.
* **DRT_DELETE-2** The product shall support an export and import of all of the relevant configuration, inventory and secrets that is used to configure the system.
* **DRT_DELETE-2** If import and export of data is available, the related data transfer shall use a secure channel.

# 6 Assessment criteria for compliance with technical requirements