Commit 7acf89f6 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Merge branch 'sru-definition' into 'main'

SRU definition from Uli and Pai

See merge request cyber/stan4cr2/en-304-621!11
parents fd8c2e4f ff1d59ab
Loading
Loading
Loading
Loading
+7 −4
Original line number Diff line number Diff line
@@ -216,6 +216,9 @@ For the purposes of the present document, the following terms apply:

1. **Operating System (OS)**: Software products with digital elements that provide an abstract interface of the underlying hardware and control the execution of software, and that may provide services such as computing resource management and configuration, scheduling, input-output control, managing data, and providing an interface through which applications interact with system resources and peripherals. This category includes but is not limited to real-time operating systems, general-purpose and special-purpose operating systems.
1. **Identity Provider**:
1. **Service Requesting Users (<a name="_term_.SRU">SRU</a>)**: These users rely on the correct functioning of the NEs that are controlled and maintained from the NMS. SRUs do not care about the connected NEs and have no interface to login to the NMS. SRUs can be both, humans or devices and all are dependent to the connected NEs. The number of NE-connected SRUs can vary from a single person up to thousands per NE device, and is in principle not limited. For clarification of the risk factors, and as regulators define the criticality of a facility operation by the number of affected SRUs for the case a NE ceased its service, its relevant for the present document.
1. **User**: This is the person having the credentials to login to the NMS to operate administrative actions to control and maintain the NE.


## 3.2 Abbreviations

@@ -373,12 +376,12 @@ The security profile requirements reflects the intented deployment of the NMS.
The risk factors identified by the risk assessment in Annex C are grouped into risk categories and assigned unique identifiers below.
These risks are grouped into risk categories and assigned unique identifiers below.

-   Number of affected Users <mark>change this to affected elements? define the user better?</mark>
-   Number of affected Service Requesting Users [<a href="#_term_.SRU">SRU</a>]

    -   **Rationale**: the affected user base should be accounted for in the risk definition
    -   **[AUSR-L-0]** single household or a small business
    -   **[AUSR-L-1]** medium or large sized company with possibly multiple operation sites
    -   **[AUSR-L-2]** local CSP
    -   **[AUSR-L-0]** single household or a small business, small ammount of SRUs
    -   **[AUSR-L-1]** medium or large sized company with possibly multiple operation sites, medium ammount of SRUs
    -   **[AUSR-L-2]** CSP, large ammount of SRUs

-   Complexity of managed network element implementation