Commit 81f90e04 authored by August Bournique's avatar August Bournique Committed by Santeri Toikka
Browse files

SOme grammar and readability edits.

parent d0a338ef
Loading
Loading
Loading
Loading
+9 −7
Original line number Diff line number Diff line
@@ -396,23 +396,25 @@ Following list of essential functions keep the NMS self-secure and correct funct

## 4.8 Operational Environment

The technical requirements of the present document apply under the environmental profile for operation of the product in accordance with its intended use.
The technical requirements of the present document apply to the operational and environmental profiles of a Network Managment System in accordance with its intended use.

### 4.8.x Applying encryption in RFC 1122

![Figure 4.8.x-1: OSI-model and RFC 1122](./media/ops_env_OSI_model.drawio.png)

The Service Requesting Users are often identified from the ability to communicate with the managed device in the link layer.
Fixed access network protocols operating in lower levels of the networking stack do not often have encryption available.
The subscriber line traffic is forwarded as-is without modifying the content or wrapping the traffic into layers of encryption.
A product's Service Requesting Users are often identified from the ability to communicate with the managed device in the link layer.
When considering the need for encryption, it is notable that encryption is often unavailable for fixed access network protocols operating in lower levels of the networking stack.

If the managed device is a router, it can be often configured to send and receive traffic from a configured Virtual Private Network.
For example, subscriber line traffic is forwarded to the network without modifying the content or wrapping the traffic with layers of encryption.

Likewise, when a managed device is a router, it can often be configured to send and receive traffic from a Virtual Private Network.
Addressing the VPN security is outside of this document.

In the Radio Access Networking (RAN) the protocol family in use, like IEEE 802, defines what protocols are available and what chipher suites can be used to protect the traffic.
Encryption may also be beyond the control of the manufacturer. In the Radio Access Networking (RAN), the protocol family in use, like IEEE 802, defines what protocols are available and what chipher suites can be used to protect the traffic.
Through out the multiple possible links in the RAN backhaul, it is possible that the traffic traverses unencrypted.
For example, routing a remote site traffic through satelites can end up in a situation, where trunk traffic is broadcasted to the ground station and near areas of it.
Therefore it is next to impossible to verify how the underlying network is configured when the traffic exits the control region of the product. This is noted later in [REQ-GEN-4] under [General requirements](#51-general).

Considering these and similar scenartios, it is next to impossible to verify how the underlying network is configured when the traffic exits the control region of the product. This is noted later in [REQ-GEN-4] under [General requirements](#51-general).

### 4.8.x System isolation