Commit 5e930881 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Formatting improvements

parent b0703be2
Loading
Loading
Loading
Loading
+253 −166
Original line number Diff line number Diff line
@@ -204,51 +204,53 @@ For the purposes of the present document, the following symbols apply:

For the purposes of the present document, the abbreviations given in and the following apply:

`2FA   Two Factor Authentication`  
`ABAC  Attribute-Based Access Control`  
`ACM   Agreed Cryptographic Mechanisms`  
`API   Application Programming Interface`  
`CPU   Central Processing Unit`  
`CRA   Cyber Resilience Act`  
`CSP   Communication System Provider`  
`CVE   Common Vulnerabilities and Exposures`  
`DB    Database`  
`DNS   Domain Name Server`  
`DHCP  Dynamic Host Configuration Protocol`  
`ER    Essential Requirement`  
`GDPR  General Data Protection Regulation`  
`GUI   Graphical User Interface`  
`IAM   Identity and Access Management`  
`IdP   Identity Provider`  
`ICT   Information and Communication Technology`  
`IoT   Internet of Things`  
`IP    Internet Protocol`  
`ISO   International Organization for Standardization`  
`MDM   Mobile Device Management`  
`NE    Network Element`  
`NIST  National Institute of Standards and Technology`  
`NMS   Network Management System`  
`OCI   Open Container Initiative`  
`OS    Operating System`  
`OT    Operational Technology`  
`PAN   Personal Area Network`  
`PC    Personal Computer`  
`PIA   Privacy Impact Assessments`  
`PII   Personally Identifiable Information`  
`PKI   Public Key Infrastructure`  
`RDPS  Remote Data Processing Solution`  
`RTO   Recovery Time Objective`  
`SCC   Security Category Classes`  
`SDK   Software Development Kit`  
`SDN   Software Defined Networks`  
`SIEM  Security Information and Event Management`  
`SIF   Social Interactive Function`  
`SOAR  Security Orchestration Automation and Response`  
`SRU   Service Requesting Users`  
`TLS   Transport Layer Security`  
`TR    Technical Requirement`  
`UC    Use Case`  
`VPN   Virtual Private Network`  
```
2FA   Two Factor Authentication
ABAC  Attribute-Based Access Control
ACM   Agreed Cryptographic Mechanisms
API   Application Programming Interface
CPU   Central Processing Unit
CRA   Cyber Resilience Act
CSP   Communication System Provider
CVE   Common Vulnerabilities and Exposures
DB    Database
DNS   Domain Name Server
DHCP  Dynamic Host Configuration Protocol
ER    Essential Requirement
GDPR  General Data Protection Regulation
GUI   Graphical User Interface
IAM   Identity and Access Management
IdP   Identity Provider
ICT   Information and Communication Technology
IoT   Internet of Things
IP    Internet Protocol
ISO   International Organization for Standardization
MDM   Mobile Device Management
NE    Network Element
NIST  National Institute of Standards and Technology
NMS   Network Management System
OCI   Open Container Initiative
OS    Operating System
OT    Operational Technology
PAN   Personal Area Network
PC    Personal Computer
PIA   Privacy Impact Assessments
PII   Personally Identifiable Information
PKI   Public Key Infrastructure
RDPS  Remote Data Processing Solution
RTO   Recovery Time Objective
SCC   Security Category Classes
SDK   Software Development Kit
SDN   Software Defined Networks
SIEM  Security Information and Event Management
SIF   Social Interactive Function
SOAR  Security Orchestration Automation and Response
SRU   Service Requesting Users
TLS   Transport Layer Security
TR    Technical Requirement
UC    Use Case
VPN   Virtual Private Network
```

# 4 Product context

@@ -1715,6 +1717,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.1 CYB_GENERAL-1

**Objective:** Product dependencies to external services and systems are documented and understood.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -1740,6 +1743,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.2 CYB_GENERAL-2

**Objective:** Product dependencies to external services and systems are documented and understood.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -1765,7 +1769,9 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.3 CYB_GENERAL-3

**Objective:** Dependencies to OS capabilities are documented and understood.

**Preparation:** None

**Activities:**

1. Study the technical documentation.
@@ -1783,6 +1789,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.4 CYB_GENERAL-4

**Objective:** New devices added into the management pool are able to adopt the trust initialised with the system.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -1809,7 +1816,9 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.5 CYB_GENERAL-5

**Objective:** To understand and to be able to take control over the keys used in confidentiality and integrity protection.

**Preparation:** None

**Activities:**

1. Study the technical documentation.
@@ -1827,7 +1836,9 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.4 CYB_GENERAL-6

**Objective:** To understand and to be able to take control over the keys used in confidentiality and integrity protection.

**Preparation:** None

**Activities:**

1. Study the technical documentation.
@@ -1848,6 +1859,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.1.7 CYB_GENERAL-7

**Objective:** Where multiple monitoring sources all operate they shall have consistent system time where any drift or lack of synchronization shall be accurately documented and notification provided to administrator.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -1872,6 +1884,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.2.1 CYB_OPS-1

**Objective:** The product user is able to meet the expectations of the product with the operational environment.

**Preparation:**

1. Study the technical documentation.
@@ -1895,6 +1908,7 @@ For each cybersecurity requirements defined in clause 5, the following clauses s
#### 6.2.2.2 CYB_OPS-2

**Objective:** To understand what kind of connectivity the product is using.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -1974,7 +1988,9 @@ Verify that:
### 6.4.1 SBD_TECH-1

**Objective:** Protect the integrity of the data.

**Preparation:** None

**Activities:**

1. Study the technical documentation.
@@ -1997,6 +2013,7 @@ Verify that:
### 6.4.2 SBD_TECH-2

**Objective:** Enable transition to safer cryptographies.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -2024,6 +2041,7 @@ Verify that:
### 6.5.1 SU_UPDATE-1

**Objective:** Prevent exploitation of known exploitable vulnerability

**Preparation:**

1. Examine public or private vulnerability information sources and select a recently fixed vulnerability (preferably the most recently fixed).
@@ -2055,7 +2073,9 @@ Verify that:
### 6.5.2 SU_UPDATE-2

**Objective:** Responsibility of OS level upgrades can be elsewhere outside of the system control.

**Preparation:** None

**Activities:**

1. Study the technical documentation.
@@ -2071,7 +2091,12 @@ Verify that:

### 6.5.3 SU_UPDATE-3

**Preparation:** Program a test source providing an authentic and integrity correct update package.  
**Objective:**

**Preparation:**

1. Program a test source providing an authentic and integrity correct update package.

**Activities:**

* Operate the test update server.
@@ -2380,6 +2405,7 @@ Verify that:
### 6.6.1 AAC_AUTH-1

**Objective:** Support reasonable identity management.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2405,6 +2431,7 @@ Verify that:
### 6.6.2 AAC_AUTH-2

**Objective:** Prevent accidental breaches due to lack of oversight.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2430,6 +2457,7 @@ Verify that:
### 6.6.3 AAC_AUTH-3

**Objective:** Verify the important users through other means than one.

**Preparation:**

1. Study the technical documentation how to interact with the system;
@@ -2454,6 +2482,7 @@ Verify that:
### 6.6.4 AAC_AUTH-4

**Objective:** Have an ability to adopt the system users entity context practices.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2479,6 +2508,7 @@ Verify that:
### 6.6.5 AAC_AUTH-5

**Objective:** Limit the user access to a reasonable set of rights.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2504,6 +2534,7 @@ Verify that:
### 6.6.6 AAC_AUTH-6

**Objective:** Protect the control functions and the data.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2555,6 +2586,7 @@ Verify that:
### 6.6.8 AAC_AUTH-8

**Objective:** Ensure auditability of the system.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2580,6 +2612,7 @@ Verify that:
### 6.6.10 AAC_AUTH-9

**Objective:** Ensure privileged action correctens a the time of the execution.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2605,6 +2638,7 @@ Verify that:
### 6.6.11 AAC_AUTH-10

**Objective:** Ensure auditability of the system.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2631,6 +2665,7 @@ Verify that:
### 6.6.12 AAC_AUTH-11

**Objective:** Ensure auditability of the system.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2657,6 +2692,7 @@ Verify that:
### 6.6.1.1 AAC_MACHINE-1

**Objective:** Make pre-shared keys and fixed passwords obsolete.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2682,6 +2718,7 @@ Verify that:
### 6.6.1.2 AAC_MACHINE-2

**Objective:** Prevent general super user access rights for M2M traffic IAM.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2710,6 +2747,7 @@ Verify that:
### 6.7.1 CON_INGEST-1

**Objective:** Protect the ingested data confidentiality.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2740,6 +2778,7 @@ Verify that:
### 6.7.2 CON_INGEST-2

**Objective:** Protect the ingested data confidentiality.

**Preparation:**

1. Extending the assessment defined in [6.7.1 CON_INGEST-1](#671-con_ingest-1)
@@ -2763,6 +2802,7 @@ Verify that:
### 6.7.3 CON_INGEST-3

**Objective:** Protect the ingested data confidentiality.

**Preparation:**

1. Extending the assessment defined in [6.7.1 CON_INGEST-1](#671-con_ingest-1)
@@ -2796,6 +2836,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.7.1.2 CON_CRYPTO-2

**Objective:** Prevent attackers from modifying the connectivity to a more favorable cipher suite.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2844,7 +2885,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.7.2.2 CON_CHANNEL-2

**Objective:** Mutual authentication ensures that blind trust is not part of the system design.

**Preparation:** None

**Activities:**

1. Study the technical documentation.
@@ -2865,6 +2908,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.8.1 INT_CONF-1

**Objective:** Protect the management actions and the interaction with the system enabling only secure channels.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2890,6 +2934,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.8.1.1 INT_CONF-2

**Objective:** Prevent the use of old keys.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2919,6 +2964,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.8.1.3 INT_CONF-3

**Objective:** Prevent the use of old keys.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2946,7 +2992,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.8.2.1 INT_ROTATE-1

**Objective:** When employees and administrators roles change, the related keys shall change accordingly.

**Preparation:** None

**Activities:**

1. Study the technical documentation.
@@ -2966,6 +3014,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.8.2.2 INT_ROTATE-2

**Objective:** New devices can be initialised with the shared secrets and trust anchors.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2989,6 +3038,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.8.2.3 INT_ROTATE-3

**Objective:** Prevent the use of old keys.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3015,6 +3065,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.9.1 DM_RETENTION-1

**Objective:** Ensure that the product user understands what data is being collected.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3040,6 +3091,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.9.1 DM_RETENTION-2

**Objective:** Ensure that the product user understands what data is being collected.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3065,6 +3117,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.9.1 DM_RETENTION-3

**Objective:** Ensure that the product user understands what data is being collected.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3091,6 +3144,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.10.1 AP_HA-1

**Objective:** Events by changes of the product itself that impact the product availability do not render the product behaviour unpredictable. The product keeps the availability time definitions.

**Preparation:**

1.  Have the product initialised and available with the default configuration and required credentials.
@@ -3115,6 +3169,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.10.2 AP_HA-2

**Objective:** The changes in the system availability are noticed.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -3140,6 +3195,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.10.3 AP_HA-3

**Objective:** The user understands how the system behaves under different conditions and can make a disaster recovery plan for the operation.

**Preparation:**

1.  Have the product initialised and available with the default configuration and required credentials.
@@ -3172,6 +3228,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.10.4 AP_HA-4

**Objective:** The technical documentation provides explanations on how the system behaves under different conditions, enabling the user to develop a disaster recovery plan for the operation.

**Preparation:** None

**Activities:**
@@ -3285,6 +3342,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.11.1.1 IM_SEGMENT-1

**Objective:** Protect the interface on unclassified traffic.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3309,6 +3367,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.11.1.2 IM_SEGMENT-2

**Objective:** Protect the interface on unclassified traffic.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3335,6 +3394,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.11.1.3 IM_SEGMENT-3

**Objective:** Protect the interface on unclassified traffic.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3363,6 +3423,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.12.1 MAS_TECH-1

**Objective:** How the product communicates is understood and documented.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -3389,6 +3450,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.12.2 MAS_TECH-2

**Objective:** How the product communicates is understood and documented.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -3419,6 +3481,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.13.1 EMM_ROUTE-1

**Objective:** Protect the network from compromised devices.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -3443,6 +3506,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.13.2 EMM_ROUTE-2

**Objective:** Protect the network from compromised devices.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -3467,6 +3531,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
### 6.13.3 EMM_ROUTE-3

**Objective:** Protect the network from compromised devices.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
@@ -3496,6 +3561,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.1 MON_LOG-1

**Objective:** Protect the logs from alteration.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3524,6 +3590,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.2 MON_LOG-2

**Objective:** Protect the logs from alteration.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3550,6 +3617,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.3 MON_LOG-3

**Objective:** Protect the logs leaking information.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3576,6 +3644,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.4 MON_LOG-4

**Objective:** Protect the logs from alteration.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3601,6 +3670,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.5 MON_LOG-5

**Objective:** Make it possible to systemically analyse managed element behavior.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3628,6 +3698,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.6 MON_LOG-6

**Objective:** Make it possible to systemically analyse whole system behavior.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3655,6 +3726,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.7 MON_LOG-7

**Objective:** Make it possible to systemically analyse system boot behavior.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3682,6 +3754,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.8 MON_LOG-8

**Objective:** Prevent a possible attacker to clear its traces by deleting the actions done in the system by distorting the history.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3708,6 +3781,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.9 MON_LOG-9

**Objective:** Prevent a possible attacker to clear its traces by deleting the actions done in the system by distorting the history.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3734,6 +3808,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.10 MON_LOG-10

**Objective:** Prevent a possible attacker to clear its traces by deleting the actions done in the system by distorting the history.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3761,8 +3836,11 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.11 MON_LOG-11

**Objective:** Reduces vendor lock-in and supports incident response and evidence portability.

**Preparation:** None

**Activities:** None

**Verdict:**

1. Pass if export is available, documented, and preserves essential fields.
@@ -3775,6 +3853,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.12 MON_LOG-12

**Objective:** Ensure operations visibility in the third party connected system.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -3801,8 +3880,11 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.1.13 MON_LOG-13

**Objective:** Enables audit replay and accountability for automated control planes. Reduces ambiguity in incident investigations.

**Preparation:** None

**Activities:** None

**Verdict:**

1. Pass if each configuration change can be attributed to actor and context with retrievable references.
@@ -3817,7 +3899,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.2.1 MON_METRICS-1

**Objective:** Verifies the ingestion pipeline design upholds integrity and confidentiality requirements.

**Preparation:** None

**Activities:**

1. Study the technical documentation.
@@ -3836,6 +3920,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.2.2 MON_METRICS-2

**Objective:** Stored data wiping or overwriting can always be recognized.

**Preparation:**

1. Have the product initialised and available with the default configuration;
@@ -3857,6 +3942,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
#### 6.14.2.3 MON_METRICS-3

**Objective:** The user has explanations about the meaning of each metric and is enabled to interpret it. Furthermore, it clarifies the relevance of collected metric data.

**Preparation:**

1.  Have the product initialised and available with the default configuration and required credentials.
@@ -3956,6 +4042,7 @@ Outcomes:
### 6.15.1 DRT_DELETE-1

**Objective:** Remove

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.