@@ -124,7 +124,7 @@ The Harmonised Standard shall have appropriate transposition periods specified.
The Technical Body may propose different dates to the default ones (3, 6, 18). Technical Bodies who wish to propose different dates are advised to indicate this clearly in the approved committee draft.
| Date of latest announcement of this EN (doa): | 3 months after ETSI publication |
| Date of latest publication of new National Standard | |
| or endorsement of this EN (dop/e): | 6 months after doa |
@@ -225,18 +225,20 @@ For the purposes of the present document, the following terms apply:
For the purposes of the present document, the following abbreviations apply:
`CRA Cyber Resilience Act`
`OS Operating System`
`IDP Identity Provider`
`VPN Virtual Private Network`
`SIEM Security Information and Event Management Systems`
`NMS Network Management System`
`2FA Two Factor Authentication`
`CSP Communication System Provider`
`SDN Software Defined Networks`
`GUI Graphical User Interface`
`NE Network Element`
`MDM Mobile Device Management`
```
CRA Cyber Resilience Act
OS Operating System
IDP Identity Provider
VPN Virtual Private Network
SIEM Security Information and Event Management Systems
NMS Network Management System
2FA Two Factor Authentication
CSP Communication System Provider
SDN Software Defined Networks
GUI Graphical User Interface
NE Network Element
MDM Mobile Device Management
```
# 4 Product context
@@ -329,6 +331,7 @@ The affected Service Requesting Users base is small like in:
The main focus of an IoT network is often data collection, whereas the NMS usually visualizes the collected data metrics to the end-user. The NMS-analysis of the data metrics can be automated including the triggering of warnings, alarms, or even actions based on discovered abnormal events. The NMS has limited computational capacities and consumes a low amount of power.
The NMS controls the configuration of the connected devices. As a minimum, the NMS maintains
1. an inventory of devices that are part of the managed network,
1. establishes and maintains a trust-based relation between itself and the device.
@@ -428,7 +431,7 @@ If the actual use case cannot be clearly assigned, the manufacturer shall includ
@@ -480,6 +483,7 @@ An NMS can be formed by a compilation or collaboration of different subsystems i
The security functions may be implemented inside one or more of the subsystems that form the NMS. The NMS can thereby be operated by an OS package manager or other systems which also belong to the NMS and are in scope of the present standard.
The NMS documentation shall clarify whether a security requirement is
1. completed fulfilled by the NMS itself,
1. where it relies on support from external services and
1. to which extent it is dependent on an external service.
@@ -518,7 +522,7 @@ The following are non-technical requirements, that shall be implemented by all p
| **[REQ-EXPLOIT-4]** | Product is free of known vulnerabilities at the time it is placed on the market. |
| **[REQ-EXPLOIT-5]** | Disclosure of new vulnerabilities in the application dependencies are proactively monitored. |
| **[REQ-EXPLOIT-6]** | Application design makes it possible to upgrade the OS while keeping the set High Availability targets. |
@@ -580,7 +584,6 @@ Later [Section 5.3 Risk Mitigations](#53-risk-mitigations) combines these genera
Technical requirements:
-**[REQ-TECH-0]** An network management system shall implement appropriate cryptographic libraries to allow the protection to the requirements of the forseeable use.
-**[REQ-TECH-1]** The product is shipped without undocumented interfaces.
-**[REQ-TECH-2]** Any administrative action shall be recorded for audit purposes.
@@ -1822,7 +1824,7 @@ Other Union legislation may be applicable to the product(s) falling within the s
The \"Change history/Change request (history)\" annex shall be included in every revised or amended harmonised standard and shall contain information concerning significant changes that have been introduced by it. It shall be presented as a table.