@@ -291,6 +291,25 @@ Aggregate product can have components, like OS and virtual networking interfaces
Manufacturer shall be responsible of implementing all security measurments regardless of what subcomponents are in use.
For each network management system placed on the market, the manufacturer shall develop a threat model and risk profile of the forseeable use of the network management system, and shall consider the interplay between:
- complexity of forseeable use
- likelihood of an incident, given the forseeable use
- impact of an incident, given the forseeable use
These risks are grouped into risk categories and assigned unique identifiers below.
- Number of affected Users
-**Rationale**: the affected user base should be accounted for in the risk calculation
-**[AUSR-L-0]** single household or a small business
-**[AUSR-L-1]** medium or large sized company with possibly multiple operation sites
-**[AUSR-L-2]** local CSP
-**[AUSR-L-0-RQ-1]** An network management system shall implement appropriate cryptographic libraries to allow the protection of the provisioned configuration according to the requirements of the forseeable use.
-**[AUSR-L-1-RQ-1]** An network management system which supports medium or larger enterprise networks shall implement and document appropriate safeguards to ensure the validity of users identity according to the requirements of the forseeable use.