Commit 5b69ba65 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Moved distribution of security functions

parent 51e46d6b
Loading
Loading
Loading
Loading
+0 −9
Original line number Diff line number Diff line
@@ -381,15 +381,6 @@ Following list of essential functions keep the NMS self-secure and correct funct

## 4.10 Distribution of security functions

An NMS can be formed by a compilation or collaboration of different subsystems in a local distance but within the same management network and within the equal operational environment.
The security functions may be implemented inside one or more of the subsystems that form the NMS. The NMS can thereby be operated by an OS package manager or other systems which also belong to the NMS and are in scope of the present standard.

The NMS documentation shall clarify whether a security requirement is

1. completed fulfilled by the NMS itself,
1. where it relies on support from external services and
1. to which extent it is dependent on an external service.

### 4.10.1 External security functions, not in scope of the present document

The following cybersecurity functionalities can be handled from components outside the product:
+9 −0
Original line number Diff line number Diff line
@@ -445,6 +445,15 @@ A managed device can have a configuration port, a management API, a firmware upd

<mark>Editor's Note: The clause should explain how the security functions are distributed among the product and its environment, referencing as appropriate elements of the operational environment defined in prior clauses. This analysis is not limited to which security functions products expect to get but should also explain which functions they themselves provide.</mark>

An NMS can be formed by a compilation or collaboration of different subsystems in a local distance but within the same management network and within the equal operational environment.
The security functions may be implemented inside one or more of the subsystems that form the NMS. The NMS can thereby be operated by an OS package manager or other systems which also belong to the NMS and are in scope of the present standard.

The NMS documentation shall clarify whether a security requirement is

1. completed fulfilled by the NMS itself,
1. where it relies on support from external services and
1. to which extent it is dependent on an external service.

## 4.5 Users

<mark>Editor's Note: Some common definition of user categories are proposed in clause 3.1 above for consistency across vertical standards. Users can include both integrators and end users (individual or group / consumer or organisation), as well as users with privileged rights or professional training such as administrators. Users can be professional users or consumers and may have different levels of cybersecurity knowledge. Both professional and less experienced users may also have disabilities and may be using assistive technology to access the product. In addition, where a product is used in a public space there may be indirect users who are impacted by the device and whose cybersecurity needs should be considered.</mark>