@@ -235,7 +235,8 @@ The security profile requirements in clause X reflect use cases and intended dep
Risk factor analysis of all appropriate risk factors can be combined to determine an overall risk of the product and label its risk as low, medium, or high. With this approach, each risk factor provides a description of high or low risk related to a particular aspect of the product and when combined a way to judge its overall security needs.
The risk is combination of likelihood and impact.
Each risk factor has instructions when the product should be evaluated in high or low in the respected categories.
Each risk factor is evaluated using defined criteria for likelihood and impact. The resulting risk level is determined as low, medium, or high according to Table 4.5-1.
The set of resulting risk levels is then used to determine the applicable requirements in clause 5.
The end result is a three tier low-medium-high evaluation of that given risk factor.
A set of risk factors is used to determine what requirements apply to the product in the later section [5 Requirements specifications](#5-requirements-specifications).
@@ -259,7 +260,7 @@ The number of affected Service Requesting Users [<a href="#_term_.SRU">SRU</a>]
**Rationale:** The affected user base impacts the risk definition.
[SRU]<br/> risk **likelihood** is **low**, where:
- The NMS's managed network has welldefined traffic.
- The NMS's managed network has well-defined traffic patterns.
- The NMS's managed network has only a small variety of traffic classes, for example: IoT network data collection and software updates.
- The NMS's managed network's SRUs are other devices with well-known communication needs.
@@ -309,7 +310,7 @@ The expectations on security are a sum of deployment, its environment, likelihoo
**Key:** [NIS2] </br>
**Rationale:** The NIS2 [i.16] identifies entities that require higher level of protection. The important and essential classifications are combined, as the NIS2 provides no product related additional cybersecurity requirements based on the entity classification. Additional security mechanisms can be and are definied on national level.
-The deployment context has other mechanisms that helps to identify and react to the security compromises
The deployment context may include additional mechanisms to detect and respond to security compromise.
[NIS2] </br> risk level is **low** if:
- NMS is intended for or foreseaably used to manage networks whose NIS2 status is undefined.
@@ -382,13 +383,13 @@ Following list of essential functions keep the NMS self-secure and correct funct
- Network element configuration and change management
- The NMS will use the appropriate level of access control to maintain identity and actions each system actor can take
-Performance metrics assuring that the operation of the network is in the nominal levels
-Collection and evaluation of performance metrics to support monitoring of network operation.
- Fault detection, reaction and recovery from fail state
- Functional resilience in terms of maintaining correct operation under abnormal network conditions, e.g., connection loss to managed elements.
- Functional resilience in case of
1. loss of connectivity to connected managed elements totally or partially,
2.to required network services for example time stamps and backup, and
3. power off.
- Functional resilience in the event of
1.loss of connectivity to managed elements
1. loss of required supporting network services such as time synchronization or backup services
1. or loss of power.
- Dynamic routing and switching control based on requests. Used extensively with Software Defined Networks.
- Device discovery, inventory building and depending on the use case topology map generation.
- Produce logs and traces for security and operational analysis