Commit 60a97dbf authored by Santeri Toikka's avatar Santeri Toikka
Browse files

References and abbreviations

parent e9f2fce5
Loading
Loading
Loading
Loading
+27 −16
Original line number Diff line number Diff line
@@ -196,11 +196,13 @@ The following referenced documents may be useful in implementing an ETSI deliver

- <a name="_ref_i.1">[i.1]</a> EU 2024/2847 "Cyber Resilience Act"
- <a name="_ref_i.2">[i.2]</a> ETSI hEN IAM
- <a name="_ref_i.3">[i.3]</a> ETSI EN 304 620 "VPN"
- <a name="_ref_i.3">[i.3]</a> ETSI EN 304 620 "Virtual Private Networks (VPNs)"
- <a name="_ref_i.4">[i.4]</a> CEN/CLC EN 50XXX-4 "VPN"
- <a name="_ref_i.5">[i.5]</a> ETSI EN 304 626 "Essential cybersecurity requirements for operating systems"
- <a name="_ref_i.6">[i.6]</a> ETSI hEN PKI
- <a name="_ref_i.7">[i.7]</a> ETSI hEN SIEM
- <a name="_ref_i.6">[i.6]</a> ETSI EN 304 624 "PKIs and certificate issuance software"
- <a name="_ref_i.7">[i.7]</a> ETSI EN 304 622 "Essential cybersecurity requirements for Security information and event management (SIEM) systems"
- <a name="_ref_i.8">[i.8]</a> ETSI EN 304 627 "Router, modems and switches"
- <a name="_ref_i.9">[i.9]</a> ETSI EN 304 642 "Cybersecurity Requirements for Telecommunication Systems"

# 3 Definition of terms, symbols and abbreviations

@@ -218,9 +220,12 @@ For the purposes of the present document, the following terms apply:
For the purposes of the present document, the following abbreviations apply:

| Abbreviation | Description                                       |
|--------------|----------------|
| ------------ | ------------------------------------------------- |
| CRA          | Cyber Reciliensy Act                              |
| OS           | Operating System                                  |
| IDP          | Identity Provider                                 |
| VPN          | Virtual Private Network                           |
| SIEM         | Security information and event management systems |

# 4 Product context

@@ -249,6 +254,11 @@ The following types of products have reduced or varied requirements under Regula
10. Testing and unfinished versions as defined in recital 37; Article 4, 2-3 <a name="_ref_i.1">[i.1]</a>;
11. Products Placed on the Market Prior to December 11, 2027 as defined in CRA article 69 <a name="_ref_i.1">[i.1]</a>.

The following are products and features are covered by separate standard.

12. Topics covered in "Cybersecurity Requirements for Telecommunication Systems" <a name="_ref_i.9">[i.9]</a>;
13. That CEN/CLC industrial network management systems stuff under EN-204-621b <a name="_ref_i.4">[i.4]</a>; <mark>define better</mark>

## 4.3 Product overview and architecture

> Explain the overall architecture and relationship among the parts of the products. Use diagrams if that is helpful.
@@ -357,9 +367,10 @@ There can be multple devices in the same network, and the NMS provides supportin
## 4.5 Security levels

> List the security levels and the use cases that correspond to them.
> The security level requirements reflects the intented deployment of the NMS.
> The functionality requirements are cumulative.
> High risk deployment shall implement the lower risk functionalities.

The security level requirements reflects the intented deployment of the NMS.
The functionality requirements are cumulative.
High risk deployment shall implement the lower risk functionalities.

| Deployment risk | Required functionality                        |
| --------------- | --------------------------------------------- |
@@ -414,11 +425,11 @@ The technical requirements of the present document apply under the environmental

> Describe the classes of users for this product, as differentiated by sophistication in understanding and taking responsibility for security risks. More sophisticated users can be expected to follow more instructions and cope with higher levels of unmitigated risks. Suggestions:
>
> * General public
> * Children
> * Assistants to primary user
> * IT professionals
> * Systems integrators
> - General public
> - Children
> - Assistants to primary user
> - IT professionals
> - Systems integrators

## 4.9 Risk distribution among components