Commit 659a54e5 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Editorial changes to formatting

parent d9940832
Loading
Loading
Loading
Loading
+5 −1
Original line number Diff line number Diff line
@@ -1184,7 +1184,8 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P

If the deliverable contains or requires an operating system the operating system is expected to be regularly updated and maintained.
Depending on the chosen delivery method, the maintenance of the operating system can be provided by the customer of the product.
Note that a container always has an operating system.

> NOTE: A container always has an operating system.

* **KEV_EXPLOIT-1** If automateable vulnerability scanners are available the product shall satisfy the following with respect to the most comprehensive of such scanners:
  * The product shall have no known exploitable vulnerabilities discovered by scans.
@@ -1218,6 +1219,8 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
* **SU_UPDATE-2** The product shall have divorced OS and Application update procedures which makes it possible to obtain the set High Availability targets when the operational environment makes this possible.
* **SU_UPDATE-3** The product shall ensure that the product can be updated at the time of first use to address all known exploitable vulnerabilities which were discovered after the product's placement on the market and before that first use.

> NOTE: **SU_UPDATE-3** is not conditional, because even in clustering environment, where product does not control its own deployed version, the documentation of installation might point to old sources.

System updates are essential to keep the number of known vulnerabilities at a minimum.
A wide variety of threats related to secure updates may appear both prior to an update and during the update process.

@@ -1242,6 +1245,7 @@ Therefore, application of updates needs to be performed in a manner that maintai
* **SU_UPDATES-7:** The product shall provide a way for the system user to postpone or re-schedule the application update.

The requirements **SU_UPDATES-8** to **13** are conditional due to different operative management and ownership models.

A cellphone that is connected to a corporate inventory management often has its own update manager, and the device does not rely on the centralised control.
Similarly in a modern cluster deployment, the application can not update itself, as the control is in the cluster, which makes the provisioning, scheduling and network shaping decisions for all applications running in the same context.