@@ -108,12 +108,14 @@ IPRs essential or potentially essential to normative deliverables may have been
Pursuant to the ETSI Directives including the ETSI IPR Policy, no investigation regarding the essentiality of IPRs, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the present document.
## Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners. ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
**DECT™** , **PLUGTESTS™** , **UMTS™** and the ETSI logo are trademarks of ETSI registered for the benefit of its Members. **3GPP™** , **LTE™** and **5G ™** logo are trademarks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. **oneM2M™** logo is a trademark of ETSI registered for the benefit of its Members and of the oneM2M Partners. **GSM**® and the GSM logo are trademarks registered and owned by the GSM Association.
# Foreword
> DRAFT FOREWORD - DO NOT CONSIDER THE CONTENT Should be written as a last item.
@@ -141,6 +143,7 @@ The Technical Body may propose different dates to the default ones (3, 6, 18). T
The Technical Body should advise the ETSI Secretariat if the above default national transposition dates are inappropriate for the particular standard.
# Modal verbs terminology
In the present document "**should** ", "**should not** ", "**may** ", "**need not** ", "**will** ", "**will not** ", "**can** " and "**cannot** " are to be interpreted as described in clause 3.2 of the [ETSI Drafting Rules](https://portal.etsi.org/Services/editHelp/How-to-start/ETSI-Drafting-Rules)(Verbal forms for the expression of provisions).
@@ -208,20 +211,24 @@ The following referenced documents may be useful in implementing an ETSI deliver
-<aname="_ref_i.1">[i.1]</a> Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
*<aname="_ref_i.2">[i.2]</a> ETSI hEN IAM
*<aname="_ref_i.3">[i.3]</a> ETSI hEN OS
*<aname="_ref_i.4">[i.4]</a> ETSI hEN PKI
*<aname="_ref_i.4">[i.5]</a> ETSI hEN SIEM
# 3 Definition of terms, symbols and abbreviations
## 3.1 Terms
This section provides terms and definitions based on CEN/CLC JTC13 WG09's work on terms and definitions, terms and definitions provided by ETSI EN 303 645/TS 103 701 and terms and definitions provided by CEN/CLC EN 18031 series.
For the purposes of the present document, the [following] terms [given in ... and the following] apply:
For the purposes of the present document, the following terms apply:
- Operating system
- IDP
1.**Operating System (OS)**: Software products with digital elements that provide an abstract interface of the underlying hardware and control the execution of software, and that may provide services such as computing resource management and configuration, scheduling, input-output control, managing data, and providing an interface through which applications interact with system resources and peripherals. This category includes but is not limited to real-time operating systems, general-purpose and special-purpose operating systems.
1.**Identity Provider**:
<mark>FIXME actually define these</mark>
<mark>FIXME add any other terms we need to define</mark>
## 3.2 Abbreviations
@@ -350,12 +357,11 @@ High risk deployment shall implement the lower risk functionalities.
Only products, which implement high risk profile can be offered for an entity classified as NIS2 critical.
| Deployment risk | Market |
| --------------- | ------------------- |
| --------------- | -------------------- |
| Low | Not targeted by NIS2 |
| Medium | NIS2 important |
| High | NIS2 critical |
## 4.5 Essential functions
> List the essential functions of the product, including:
@@ -366,8 +372,8 @@ Only products, which implement high risk profile can be offered for an entity cl
- Network element configuration
- Role based access control
- Performance metrics describing the operation
-In case of SDN: Besides metrics there are also routing/switching requests possible, which are sent from the device to the NMS or SDN controller. This would be the case if the SDN network has reactive flow rule installation enabled.
- Performance metrics assuring that the operation of the network is in the nominal levels
-Dynamic routing and switching control based on requests. Used extensively with Software Defined Networks.
<mark>FIXME more use-based functions</mark>
@@ -385,6 +391,8 @@ The technical requirements of the present document apply under the environmental
## 4.8 Risk distribution among components
> Risk can be transferred between components, for example a network interface can document that secure update of its firmware must be handled by an external program, such as an operating system. In turn, the operating system can offer the security functionality of secure updates to other components in a system.
> Describe what risks are delegated to sub-components, as well as what risk management features this product offers to things integrating it.
<mark>FIXME describe what subcomponents chip-in and how</mark>
@@ -543,12 +551,11 @@ The annex shall have a table for a clear indication of correspondence between no
**Table A.1: Relationship between the present document and<br />the requirements of EU Regulation 2024/2847**<aname="table_A.1"></a>