@@ -204,51 +204,53 @@ For the purposes of the present document, the following symbols apply:
For the purposes of the present document, the abbreviations given in and the following apply:
`2FA Two Factor Authentication`
`ABAC Attribute-Based Access Control`
`ACM Agreed Cryptographic Mechanisms`
`API Application Programming Interface`
`CPU Central Processing Unit`
`CRA Cyber Resilience Act`
`CSP Communication System Provider`
`CVE Common Vulnerabilities and Exposures`
`DB Database`
`DNS Domain Name Server`
`DHCP Dynamic Host Configuration Protocol`
`ER Essential Requirement`
`GDPR General Data Protection Regulation`
`GUI Graphical User Interface`
`IAM Identity and Access Management`
`IdP Identity Provider`
`ICT Information and Communication Technology`
`IoT Internet of Things`
`IP Internet Protocol`
`ISO International Organization for Standardization`
`MDM Mobile Device Management`
`NE Network Element`
`NIST National Institute of Standards and Technology`
`NMS Network Management System`
`OCI Open Container Initiative`
`OS Operating System`
`OT Operational Technology`
`PAN Personal Area Network`
`PC Personal Computer`
`PIA Privacy Impact Assessments`
`PII Personally Identifiable Information`
`PKI Public Key Infrastructure`
`RDPS Remote Data Processing Solution`
`RTO Recovery Time Objective`
`SCC Security Category Classes`
`SDK Software Development Kit`
`SDN Software Defined Networks`
`SIEM Security Information and Event Management`
`SIF Social Interactive Function`
`SOAR Security Orchestration Automation and Response`
`SRU Service Requesting Users`
`TLS Transport Layer Security`
`TR Technical Requirement`
`UC Use Case`
`VPN Virtual Private Network`
```
2FA Two Factor Authentication
ABAC Attribute-Based Access Control
ACM Agreed Cryptographic Mechanisms
API Application Programming Interface
CPU Central Processing Unit
CRA Cyber Resilience Act
CSP Communication System Provider
CVE Common Vulnerabilities and Exposures
DB Database
DNS Domain Name Server
DHCP Dynamic Host Configuration Protocol
ER Essential Requirement
GDPR General Data Protection Regulation
GUI Graphical User Interface
IAM Identity and Access Management
IdP Identity Provider
ICT Information and Communication Technology
IoT Internet of Things
IP Internet Protocol
ISO International Organization for Standardization
MDM Mobile Device Management
NE Network Element
NIST National Institute of Standards and Technology
NMS Network Management System
OCI Open Container Initiative
OS Operating System
OT Operational Technology
PAN Personal Area Network
PC Personal Computer
PIA Privacy Impact Assessments
PII Personally Identifiable Information
PKI Public Key Infrastructure
RDPS Remote Data Processing Solution
RTO Recovery Time Objective
SCC Security Category Classes
SDK Software Development Kit
SDN Software Defined Networks
SIEM Security Information and Event Management
SIF Social Interactive Function
SOAR Security Orchestration Automation and Response
SRU Service Requesting Users
TLS Transport Layer Security
TR Technical Requirement
UC Use Case
VPN Virtual Private Network
```
# 4 Product context
@@ -1715,6 +1717,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.1 CYB_GENERAL-1
**Objective:** Product dependencies to external services and systems are documented and understood.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -1740,6 +1743,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.2 CYB_GENERAL-2
**Objective:** Product dependencies to external services and systems are documented and understood.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -1765,7 +1769,9 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.3 CYB_GENERAL-3
**Objective:** Dependencies to OS capabilities are documented and understood.
**Preparation:** None
**Activities:**
1. Study the technical documentation.
@@ -1783,6 +1789,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.4 CYB_GENERAL-4
**Objective:** New devices added into the management pool are able to adopt the trust initialised with the system.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -1809,7 +1816,9 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.5 CYB_GENERAL-5
**Objective:** To understand and to be able to take control over the keys used in confidentiality and integrity protection.
**Preparation:** None
**Activities:**
1. Study the technical documentation.
@@ -1827,7 +1836,9 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.4 CYB_GENERAL-6
**Objective:** To understand and to be able to take control over the keys used in confidentiality and integrity protection.
**Preparation:** None
**Activities:**
1. Study the technical documentation.
@@ -1848,6 +1859,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.7 CYB_GENERAL-7
**Objective:** Where multiple monitoring sources all operate they shall have consistent system time where any drift or lack of synchronization shall be accurately documented and notification provided to administrator.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -1872,6 +1884,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.2.1 CYB_OPS-1
**Objective:** The product user is able to meet the expectations of the product with the operational environment.
**Preparation:**
1. Study the technical documentation.
@@ -1895,6 +1908,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.2.2 CYB_OPS-2
**Objective:** To understand what kind of connectivity the product is using.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -1974,7 +1988,9 @@ Verify that:
### 6.4.1 SBD_TECH-1
**Objective:** Protect the integrity of the data.
**Preparation:** None
**Activities:**
1. Study the technical documentation.
@@ -1997,6 +2013,7 @@ Verify that:
### 6.4.2 SBD_TECH-2
**Objective:** Enable transition to safer cryptographies.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -2024,6 +2041,7 @@ Verify that:
### 6.5.1 SU_UPDATE-1
**Objective:** Prevent exploitation of known exploitable vulnerability
**Preparation:**
1. Examine public or private vulnerability information sources and select a recently fixed vulnerability (preferably the most recently fixed).
@@ -2055,7 +2073,9 @@ Verify that:
### 6.5.2 SU_UPDATE-2
**Objective:** Responsibility of OS level upgrades can be elsewhere outside of the system control.
**Preparation:** None
**Activities:**
1. Study the technical documentation.
@@ -2071,7 +2091,12 @@ Verify that:
### 6.5.3 SU_UPDATE-3
**Preparation:** Program a test source providing an authentic and integrity correct update package.
**Objective:**
**Preparation:**
1. Program a test source providing an authentic and integrity correct update package.
**Activities:**
* Operate the test update server.
@@ -2380,6 +2405,7 @@ Verify that:
### 6.6.1 AAC_AUTH-1
**Objective:** Support reasonable identity management.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2405,6 +2431,7 @@ Verify that:
### 6.6.2 AAC_AUTH-2
**Objective:** Prevent accidental breaches due to lack of oversight.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2430,6 +2457,7 @@ Verify that:
### 6.6.3 AAC_AUTH-3
**Objective:** Verify the important users through other means than one.
**Preparation:**
1. Study the technical documentation how to interact with the system;
@@ -2454,6 +2482,7 @@ Verify that:
### 6.6.4 AAC_AUTH-4
**Objective:** Have an ability to adopt the system users entity context practices.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2479,6 +2508,7 @@ Verify that:
### 6.6.5 AAC_AUTH-5
**Objective:** Limit the user access to a reasonable set of rights.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2504,6 +2534,7 @@ Verify that:
### 6.6.6 AAC_AUTH-6
**Objective:** Protect the control functions and the data.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2555,6 +2586,7 @@ Verify that:
### 6.6.8 AAC_AUTH-8
**Objective:** Ensure auditability of the system.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2580,6 +2612,7 @@ Verify that:
### 6.6.10 AAC_AUTH-9
**Objective:** Ensure privileged action correctens a the time of the execution.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2605,6 +2638,7 @@ Verify that:
### 6.6.11 AAC_AUTH-10
**Objective:** Ensure auditability of the system.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2631,6 +2665,7 @@ Verify that:
### 6.6.12 AAC_AUTH-11
**Objective:** Ensure auditability of the system.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2657,6 +2692,7 @@ Verify that:
### 6.6.1.1 AAC_MACHINE-1
**Objective:** Make pre-shared keys and fixed passwords obsolete.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2682,6 +2718,7 @@ Verify that:
### 6.6.1.2 AAC_MACHINE-2
**Objective:** Prevent general super user access rights for M2M traffic IAM.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2710,6 +2747,7 @@ Verify that:
### 6.7.1 CON_INGEST-1
**Objective:** Protect the ingested data confidentiality.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2740,6 +2778,7 @@ Verify that:
### 6.7.2 CON_INGEST-2
**Objective:** Protect the ingested data confidentiality.
**Preparation:**
1. Extending the assessment defined in [6.7.1 CON_INGEST-1](#671-con_ingest-1)
@@ -2763,6 +2802,7 @@ Verify that:
### 6.7.3 CON_INGEST-3
**Objective:** Protect the ingested data confidentiality.
**Preparation:**
1. Extending the assessment defined in [6.7.1 CON_INGEST-1](#671-con_ingest-1)
@@ -2796,6 +2836,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.7.1.2 CON_CRYPTO-2
**Objective:** Prevent attackers from modifying the connectivity to a more favorable cipher suite.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2844,7 +2885,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.7.2.2 CON_CHANNEL-2
**Objective:** Mutual authentication ensures that blind trust is not part of the system design.
**Preparation:** None
**Activities:**
1. Study the technical documentation.
@@ -2865,6 +2908,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.8.1 INT_CONF-1
**Objective:** Protect the management actions and the interaction with the system enabling only secure channels.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2890,6 +2934,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.8.1.1 INT_CONF-2
**Objective:** Prevent the use of old keys.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2919,6 +2964,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.8.1.3 INT_CONF-3
**Objective:** Prevent the use of old keys.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2946,7 +2992,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.8.2.1 INT_ROTATE-1
**Objective:** When employees and administrators roles change, the related keys shall change accordingly.
**Preparation:** None
**Activities:**
1. Study the technical documentation.
@@ -2966,6 +3014,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.8.2.2 INT_ROTATE-2
**Objective:** New devices can be initialised with the shared secrets and trust anchors.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -2989,6 +3038,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.8.2.3 INT_ROTATE-3
**Objective:** Prevent the use of old keys.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3015,6 +3065,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.9.1 DM_RETENTION-1
**Objective:** Ensure that the product user understands what data is being collected.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3040,6 +3091,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.9.1 DM_RETENTION-2
**Objective:** Ensure that the product user understands what data is being collected.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3065,6 +3117,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.9.1 DM_RETENTION-3
**Objective:** Ensure that the product user understands what data is being collected.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3091,6 +3144,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.10.1 AP_HA-1
**Objective:** Events by changes of the product itself that impact the product availability do not render the product behaviour unpredictable. The product keeps the availability time definitions.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3115,6 +3169,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.10.2 AP_HA-2
**Objective:** The changes in the system availability are noticed.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3140,6 +3195,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.10.3 AP_HA-3
**Objective:** The user understands how the system behaves under different conditions and can make a disaster recovery plan for the operation.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3172,6 +3228,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.10.4 AP_HA-4
**Objective:** The technical documentation provides explanations on how the system behaves under different conditions, enabling the user to develop a disaster recovery plan for the operation.
**Preparation:** None
**Activities:**
@@ -3285,6 +3342,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.11.1.1 IM_SEGMENT-1
**Objective:** Protect the interface on unclassified traffic.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3309,6 +3367,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.11.1.2 IM_SEGMENT-2
**Objective:** Protect the interface on unclassified traffic.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3335,6 +3394,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.11.1.3 IM_SEGMENT-3
**Objective:** Protect the interface on unclassified traffic.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3363,6 +3423,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.12.1 MAS_TECH-1
**Objective:** How the product communicates is understood and documented.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3389,6 +3450,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.12.2 MAS_TECH-2
**Objective:** How the product communicates is understood and documented.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3419,6 +3481,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.13.1 EMM_ROUTE-1
**Objective:** Protect the network from compromised devices.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3443,6 +3506,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.13.2 EMM_ROUTE-2
**Objective:** Protect the network from compromised devices.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3467,6 +3531,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.13.3 EMM_ROUTE-3
**Objective:** Protect the network from compromised devices.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3496,6 +3561,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.1 MON_LOG-1
**Objective:** Protect the logs from alteration.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3524,6 +3590,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.2 MON_LOG-2
**Objective:** Protect the logs from alteration.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3550,6 +3617,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.3 MON_LOG-3
**Objective:** Protect the logs leaking information.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3576,6 +3644,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.4 MON_LOG-4
**Objective:** Protect the logs from alteration.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3601,6 +3670,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.5 MON_LOG-5
**Objective:** Make it possible to systemically analyse managed element behavior.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3628,6 +3698,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.6 MON_LOG-6
**Objective:** Make it possible to systemically analyse whole system behavior.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3655,6 +3726,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.7 MON_LOG-7
**Objective:** Make it possible to systemically analyse system boot behavior.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3682,6 +3754,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.8 MON_LOG-8
**Objective:** Prevent a possible attacker to clear its traces by deleting the actions done in the system by distorting the history.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3708,6 +3781,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.9 MON_LOG-9
**Objective:** Prevent a possible attacker to clear its traces by deleting the actions done in the system by distorting the history.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3734,6 +3808,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.10 MON_LOG-10
**Objective:** Prevent a possible attacker to clear its traces by deleting the actions done in the system by distorting the history.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3761,8 +3836,11 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.11 MON_LOG-11
**Objective:** Reduces vendor lock-in and supports incident response and evidence portability.
**Preparation:** None
**Activities:** None
**Verdict:**
1. Pass if export is available, documented, and preserves essential fields.
@@ -3775,6 +3853,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.12 MON_LOG-12
**Objective:** Ensure operations visibility in the third party connected system.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials;
@@ -3801,8 +3880,11 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.13 MON_LOG-13
**Objective:** Enables audit replay and accountability for automated control planes. Reduces ambiguity in incident investigations.
**Preparation:** None
**Activities:** None
**Verdict:**
1. Pass if each configuration change can be attributed to actor and context with retrievable references.
@@ -3817,7 +3899,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.2.1 MON_METRICS-1
**Objective:** Verifies the ingestion pipeline design upholds integrity and confidentiality requirements.
**Preparation:** None
**Activities:**
1. Study the technical documentation.
@@ -3836,6 +3920,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.2.2 MON_METRICS-2
**Objective:** Stored data wiping or overwriting can always be recognized.
**Preparation:**
1. Have the product initialised and available with the default configuration;
@@ -3857,6 +3942,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.2.3 MON_METRICS-3
**Objective:** The user has explanations about the meaning of each metric and is enabled to interpret it. Furthermore, it clarifies the relevance of collected metric data.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
@@ -3956,6 +4042,7 @@ Outcomes:
### 6.15.1 DRT_DELETE-1
**Objective:** Remove
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.