Loading EN-304-621.md +27 −45 Original line number Diff line number Diff line Loading @@ -864,36 +864,40 @@ Requirements: These requirements are generally binding, and there is no low-medium-high tiering available. <mark>Consider makgin [REQ-UPDATES-3] only for high tier one.</mark> <mark>Consider making [REQ-UPDATES-3] applicable only for high tier.</mark> ### 5.3.5 Logging <mark>AMS: Luka and Bruno are working on this. Skip for now.</mark> The monitoring requirements becomes more demanding, when the security expectation of the deployment context is more strict. When evaluating the applicability of these requirements, the highest of following risk factors define the category to follow: [NIS2] - **[REQ-LOG-0]** Adminstrative actions like logs, traces and events are recorded into a write only service or endpoint. - **[REQ-LOG-1]** The write only log or tracing storage is deployed outside of the system deployment context. - **[REQ-LOG-2]** The system reports relevant administrative operations forward to an external SIEM system. - **[REQ-LOG-3a]** The log file of events shall be protected from unauthorized access, modification, - **[REQ-LOG-3b]** have a active backup scheduled, - **[REQ-LOG-3c]** and is confidentiality protected. - **[REQ-LOG-4]** SIEM transfer format, field attributes and event descriptions are available as part of the technical documentation. For low risk: Manfacturer shall implement logging system features listed in the table below. - **[REQ-LOG-0a]:** The log file of events shall be protected from unauthorized access, modification, - **[REQ-LOG-0b]:** and is confidentiality protected. - **[REQ-LOG-1a]:** The product shall generate auditable events for: successful and failed authentication attempts, - **[REQ-LOG-1b]:** session establishment attempts with source details, - **[REQ-LOG-1c]:** session termination events with reason, - **[REQ-LOG-1d]:** session validation checks like number of concurrent sessions, - **[REQ-LOG-1e]:** and privilege escalation. - **[REQ-LOG-2a]:** The product shall log boot or initialization events: timestamped boot stage progression, - **[REQ-LOG-2b]:** component verification and initialisation actions, - **[REQ-LOG-2c]:** and recovery mode activations if in use. - **[REQ-LOG-3a]:** The product shall log: update availability, - **[REQ-LOG-3b]:** start and finish of the update download, - **[REQ-LOG-3c]:** events described by [5.3.4 Secure updates], - **[REQ-LOG-3d]:** and installation successes and failures. **Table 5.3.5-1: Logging requirements** For medium risk: | Name | [EXP-L-0] | [EXP-L-1] | | :-------------------- | :----------- | :---------- | | Entity classification | Undefined | NIS2 entity | | [REQ-LOG-0] | Required | Required | | [REQ-LOG-1] | Required | Required | | [REQ-LOG-2] | Not required | Required | | [REQ-LOG-3a] | Required | Required | | [REQ-LOG-3b] | Not required | Required | | [REQ-LOG-3c] | Not required | Required | | [REQ-LOG-4] | Not required | Required | - **[REQ-LOG-4]:** The log information shall have a active backup scheduled. - **[REQ-LOG-5]:** Adminstrative actions like logs, traces and events shall be recorded into a write only service or endpoint. <br /> For high risk: - **[REQ-LOG-6]:** The write only log or tracing storage shall be deployed outside of the system deployment context. - **[REQ-LOG-7]:** The system reports relevant administrative operations shall be forwarded to an external SIEM system. - **[REQ-LOG-8]:** SIEM transfer format, field attributes and event descriptions shall made available as part of the technical documentation. ### 5.3.6 Monitoring Loading Loading @@ -924,29 +928,7 @@ Application monitoring requirements: - **[REQ-MON-10]** GUI and API latencies are tracked and reported. - **[REQ-MON-11]** GUI and API error rates are tracked and reported. Manfacturer shall implement requirements as listed in the table below. **Table 5.3.6-1: Monitoring requirements** | Name | [COM-L-0] | [COM-L-1] | [COM-L-2] | [COM-L-3] | [6.3.6 Monitoring tests] | | :-------------------------------- | :----------- | :---------- | :---------------- | :---------- | :--------------------------- | | Complexity of the managed element | Limited IoT | Home device | Enterprise router | Basestation | | | [REQ-MON-0] | Required | Required | Required | Required | [6.3.6.0](#6360-req-mon-0) | | [REQ-MON-1] | Required | Required | Required | Required | [6.3.6.1](#6360-req-mon-1) | | [REQ-MON-2] | Required | Required | Required | Required | [6.3.6.2](#6360-req-mon-2) | | [REQ-MON-3] | Required | Required | Required | Required | [6.3.6.3](#6360-req-mon-3) | | [REQ-MON-4] | Required | Required | Required | Required | [6.3.6.4](#6360-req-mon-4) | | [REQ-MON-5] | Required | Required | Required | Required | [6.3.6.5](#6360-req-mon-5) | | [REQ-MON-6a] | Required | Required | Required | Required | [6.3.6.6](#6360-req-mon-6) | | [REQ-MON-6b] | Not required | Required | Required | Required | [6.3.6.6](#6360-req-mon-6) | | [REQ-MON-7] | Required | Required | Required | Required | [6.3.6.7](#6360-req-mon-7) | | [REQ-MON-8a] | Required | Required | Required | Required | [6.3.6.8](#6360-req-mon-8) | | [REQ-MON-8b] | Not required | Required | Required | Required | [6.3.6.8](#6360-req-mon-8) | | [REQ-MON-9] | Required | Required | Required | Required | [6.3.6.9](#6360-req-mon-9) | | [REQ-MON-10] | Required | Required | Required | Required | [6.3.6.10](#6360-req-mon-10) | | [REQ-MON-11] | Required | Required | Required | Required | [6.3.6.11](#6360-req-mon-10) | <br /> These requirements are generally binding, and there is no low-medium-high tiering available. Matching tests for these requirements are listed in [6.3.6 Monitoring tests]. Loading Loading
EN-304-621.md +27 −45 Original line number Diff line number Diff line Loading @@ -864,36 +864,40 @@ Requirements: These requirements are generally binding, and there is no low-medium-high tiering available. <mark>Consider makgin [REQ-UPDATES-3] only for high tier one.</mark> <mark>Consider making [REQ-UPDATES-3] applicable only for high tier.</mark> ### 5.3.5 Logging <mark>AMS: Luka and Bruno are working on this. Skip for now.</mark> The monitoring requirements becomes more demanding, when the security expectation of the deployment context is more strict. When evaluating the applicability of these requirements, the highest of following risk factors define the category to follow: [NIS2] - **[REQ-LOG-0]** Adminstrative actions like logs, traces and events are recorded into a write only service or endpoint. - **[REQ-LOG-1]** The write only log or tracing storage is deployed outside of the system deployment context. - **[REQ-LOG-2]** The system reports relevant administrative operations forward to an external SIEM system. - **[REQ-LOG-3a]** The log file of events shall be protected from unauthorized access, modification, - **[REQ-LOG-3b]** have a active backup scheduled, - **[REQ-LOG-3c]** and is confidentiality protected. - **[REQ-LOG-4]** SIEM transfer format, field attributes and event descriptions are available as part of the technical documentation. For low risk: Manfacturer shall implement logging system features listed in the table below. - **[REQ-LOG-0a]:** The log file of events shall be protected from unauthorized access, modification, - **[REQ-LOG-0b]:** and is confidentiality protected. - **[REQ-LOG-1a]:** The product shall generate auditable events for: successful and failed authentication attempts, - **[REQ-LOG-1b]:** session establishment attempts with source details, - **[REQ-LOG-1c]:** session termination events with reason, - **[REQ-LOG-1d]:** session validation checks like number of concurrent sessions, - **[REQ-LOG-1e]:** and privilege escalation. - **[REQ-LOG-2a]:** The product shall log boot or initialization events: timestamped boot stage progression, - **[REQ-LOG-2b]:** component verification and initialisation actions, - **[REQ-LOG-2c]:** and recovery mode activations if in use. - **[REQ-LOG-3a]:** The product shall log: update availability, - **[REQ-LOG-3b]:** start and finish of the update download, - **[REQ-LOG-3c]:** events described by [5.3.4 Secure updates], - **[REQ-LOG-3d]:** and installation successes and failures. **Table 5.3.5-1: Logging requirements** For medium risk: | Name | [EXP-L-0] | [EXP-L-1] | | :-------------------- | :----------- | :---------- | | Entity classification | Undefined | NIS2 entity | | [REQ-LOG-0] | Required | Required | | [REQ-LOG-1] | Required | Required | | [REQ-LOG-2] | Not required | Required | | [REQ-LOG-3a] | Required | Required | | [REQ-LOG-3b] | Not required | Required | | [REQ-LOG-3c] | Not required | Required | | [REQ-LOG-4] | Not required | Required | - **[REQ-LOG-4]:** The log information shall have a active backup scheduled. - **[REQ-LOG-5]:** Adminstrative actions like logs, traces and events shall be recorded into a write only service or endpoint. <br /> For high risk: - **[REQ-LOG-6]:** The write only log or tracing storage shall be deployed outside of the system deployment context. - **[REQ-LOG-7]:** The system reports relevant administrative operations shall be forwarded to an external SIEM system. - **[REQ-LOG-8]:** SIEM transfer format, field attributes and event descriptions shall made available as part of the technical documentation. ### 5.3.6 Monitoring Loading Loading @@ -924,29 +928,7 @@ Application monitoring requirements: - **[REQ-MON-10]** GUI and API latencies are tracked and reported. - **[REQ-MON-11]** GUI and API error rates are tracked and reported. Manfacturer shall implement requirements as listed in the table below. **Table 5.3.6-1: Monitoring requirements** | Name | [COM-L-0] | [COM-L-1] | [COM-L-2] | [COM-L-3] | [6.3.6 Monitoring tests] | | :-------------------------------- | :----------- | :---------- | :---------------- | :---------- | :--------------------------- | | Complexity of the managed element | Limited IoT | Home device | Enterprise router | Basestation | | | [REQ-MON-0] | Required | Required | Required | Required | [6.3.6.0](#6360-req-mon-0) | | [REQ-MON-1] | Required | Required | Required | Required | [6.3.6.1](#6360-req-mon-1) | | [REQ-MON-2] | Required | Required | Required | Required | [6.3.6.2](#6360-req-mon-2) | | [REQ-MON-3] | Required | Required | Required | Required | [6.3.6.3](#6360-req-mon-3) | | [REQ-MON-4] | Required | Required | Required | Required | [6.3.6.4](#6360-req-mon-4) | | [REQ-MON-5] | Required | Required | Required | Required | [6.3.6.5](#6360-req-mon-5) | | [REQ-MON-6a] | Required | Required | Required | Required | [6.3.6.6](#6360-req-mon-6) | | [REQ-MON-6b] | Not required | Required | Required | Required | [6.3.6.6](#6360-req-mon-6) | | [REQ-MON-7] | Required | Required | Required | Required | [6.3.6.7](#6360-req-mon-7) | | [REQ-MON-8a] | Required | Required | Required | Required | [6.3.6.8](#6360-req-mon-8) | | [REQ-MON-8b] | Not required | Required | Required | Required | [6.3.6.8](#6360-req-mon-8) | | [REQ-MON-9] | Required | Required | Required | Required | [6.3.6.9](#6360-req-mon-9) | | [REQ-MON-10] | Required | Required | Required | Required | [6.3.6.10](#6360-req-mon-10) | | [REQ-MON-11] | Required | Required | Required | Required | [6.3.6.11](#6360-req-mon-10) | <br /> These requirements are generally binding, and there is no low-medium-high tiering available. Matching tests for these requirements are listed in [6.3.6 Monitoring tests]. Loading