Commit 69c3c111 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Added references to horizontal standars

parent 40095ce9
Loading
Loading
Loading
Loading
+26 −28
Original line number Diff line number Diff line
@@ -178,6 +178,7 @@ The present document does not cover products in use in contexts other than those
The following referenced documents are necessary for the application of the present document.

-   <span id="_ref_1"></span><a name="_ref_1">[1]</a> ENISA April 2025 (Version 2.0) \"Agreed Cryptographic Mechanisms\"
-   <span id="_ref_2"></span><a name="_ref_4">[2]</a> prEN 40000-1-3 "Vulnerability Handling"

## 2.2 Informative references

@@ -200,6 +201,9 @@ The following referenced documents may be useful in implementing an ETSI deliver
-   <span id="_ref_i.11"></span><a name="_ref_i.11">[i.11]</a> EU 2025/2392 Comission implementing regulation on the technical description of the categories of important and critical products with digital elements pursuant to Regulation EU 2024/2847 (CRA)
-   <span id="_ref_i.12"></span><a name="_ref_i.12">[i.12]</a> ISO/IEC 27000:2018
-   <span id="_ref_i.13"></span><a name="_ref_i.13">[i.13]</a> NIST SP 800-63B-4 Authentication & Authenticator Management
-   <span id="_ref_i.14"></span><a name="_ref_i.14">[i.14]</a> prEN 40000-1-1 "Vocabulary"
-   <span id="_ref_i.15"></span><a name="_ref_i.15">[i.15]</a> prEN 40000-1-2 "Principles for cyber resilience"


[Mitre ATT&CK]: (https://attack.mitre.org)

@@ -630,15 +634,11 @@ More about [High Availability](#53x-high-availability) in its dedicated chapter.

### 5.1.2 Secure design, development and production

<mark>TODO</mark>

### 5.1.3 Product lifecycle management

<mark>TODO</mark>
This document will make informative reference prEN 40000-1-2 "Principles for cyber resilience" <a href="#_ref_i.15">[i.15]</a> normative, when available.

### 5.1.4 Product vulneravility management process
### 5.1.3 Product vulneravility management process

<mark>TODO</mark>
This document normatively references EN 40000-1-3 "Vulnerability Handling"<a href="#_ref_2">[2]</a> and doesn't add to the specified definitions.

## 5.2 Technical cybersecurity requirements specifications

@@ -1472,9 +1472,9 @@ Functional sufficiency assessment, “not necessary of a pure applicability requ
**Table A-1: Essential requirements mapping**

| CRA requirement                                 | Technical cybersecurity requirements                                |
| :---------------------------------------------- | :-------------------------------------------------------------------------------------- |
| :---------------------------------------------- | :------------------------------------------------------------------ |
| No known exploitable vulnerabilities            | [5.1.1 No known exploited vulnerabilities]                          |
| Secure design, development, production          | [5.1.2 Secure design, development and production], [5.1.3 Product lifecycle management] |
| Secure design, development, production          | [5.1.2 Secure design, development and production]                   |
| Secure by default configuration                 | [5.2.4 State-of-the-art cryptographic libraries]                    |
| Secure updates                                  | [5.3.4 Secure updates]                                              |
| Authentication and access control mechanisms    | [5.2.6 Role based authorisation]                                    |
@@ -1483,16 +1483,15 @@ Functional sufficiency assessment, “not necessary of a pure applicability requ
| Data minimization                               | [5.3.7 Data minimization]                                           |
| Availability protection                         | [5.3.8 High Availability]                                           |
| Minimize impact on other devices or services    | [5.3.8 High Availability]                                           |
| Limit attack surface                            | [5.1.4 Product vulneravility management process]                                        |
| Exploit mitigation by limiting incident impact  |                                                                                         |
| Limit attack surface                            | [5.1.3 Product vulneravility management process]                    |
| Exploit mitigation by limiting incident impact  | [5.2.6 Role based authorisation]                                    |
| Logging and monitoring mechanisms               | [5.3.5 Logging], [5.3.6 Metrics]                                    |
| Secure deletion and data transfer               |                                                                                         |
| Secure deletion and data transfer               | [REQ-METRICS-3], [5.2.1 Secure channel definition]                  |

[5.1 General]: #51-general
[5.1.1 No known exploited vulnerabilities]: #511-no-known-exploited-vulnerabilities
[5.1.2 Secure design, development and production]: #512-secure-design-development-and-production
[5.1.3 Product lifecycle management]: #513-product-lifecycle-management
[5.1.4 Product vulneravility management process]: #514-product-vulneravility-management-process
[5.1.3 Product vulneravility management process]: #513-product-vulneravility-management-process
[5.2 Technical cybersecurity requirements specifications]: #52-technical-cybersecurity-requirements-specifications
[5.2.1 Secure channel definition]: #521-secure-channel-definition
[5.2.2 Cryptographic key intialization and rotation]: #522-cryptographic-key-intialization-and-rotation
@@ -1522,9 +1521,8 @@ Functional sufficiency assessment, “not necessary of a pure applicability requ
| :-------------------------------------------------------- | :------------------------- | :----------- |
| [5.1 General]                                             | done                       |              |
| [5.1.1 No known exploited vulnerabilities]                | done                       | done         |
| [5.1.2 Secure design, development and production]         |                            |              |
| [5.1.3 Product lifecycle management]                      |                            |              |
| [5.1.4 Product vulneravility management process]          |                            |              |
| [5.1.2 Secure design, development and production]         | done                       |              |
| [5.1.3 Product vulneravility management process]          | done                       |              |
| [5.2 Technical cybersecurity requirements specifications] | done                       |              |
| [5.2.1 Secure channel definition]                         | done                       |              |
| [5.2.2 Cryptographic key intialization and rotation]      | done                       |              |