@@ -412,6 +412,22 @@ When management system is deployed on shared resources, the resource hierarchy,
>
>Editor's Note: What is a pocket deployment? That needs a clarification. Does that mean deployment in a from public networks isolated closed network?
>This section should also have the OSI-model and TCP/IP model opened as a reference. Crypto doesn't fit everywhere.
> An old block from !25:
The manufacturer shall describe the core requirements for the operational environment (OE). The actual protection required is linked to the criticality of the use case, and with that the OE requirements can be mapped to [SUR-L-x].
The OE for [SRU-L-0] shall ensure:
to be defined......
The OE for [SRU-L-1] shall ensure:
to be defined......
The OE for [SRU-L-2] shall ensure:
• Always available basic services the NMS requires for operation: power supply, climate control, environmental impact protection against weather, fire, earthquake, other physical impact
• Available network connections to the digital services the NMS requires or can require for operation: certificate and signature validation, backup server, logging server, timestamp server
• Physical access control to ensure access by authorized staff only
• Authorized staff shall be trained and qualified on the NMS, trusted, operate without malicious intent and act according the NMS user guidelines
## 4.9 Users
Human users of the system are natural persons, trained and qualified at NMS administrators, and authorised to manage the NMS and the connected managed elements. Administrators typically access the system through a HTTPS GUI, console, or by VPN connection.