Commit 98c81e1c authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Formatting updates

parent 11f5662f
Loading
Loading
Loading
Loading
+89 −87
Original line number Diff line number Diff line
@@ -124,7 +124,7 @@ The Harmonised Standard shall have appropriate transposition periods specified.
The Technical Body may propose different dates to the default ones (3, 6, 18). Technical Bodies who wish to propose different dates are advised to indicate this clearly in the approved committee draft.

| Proposed national transposition dates                          |                                 |
|:-|:-|
| :------------------------------------------------------------- | :------------------------------ |
| Date of latest announcement of this EN (doa):                  | 3 months after ETSI publication |
| Date of latest publication of new National Standard            |                                 |
| or endorsement of this EN (dop/e):                             | 6 months after doa              |
@@ -225,18 +225,20 @@ For the purposes of the present document, the following terms apply:

For the purposes of the present document, the following abbreviations apply:

`CRA    Cyber Resilience Act`  
`OS     Operating System`  
`IDP    Identity Provider`  
`VPN    Virtual Private Network`  
`SIEM   Security Information and Event Management Systems`  
`NMS    Network Management System`  
`2FA    Two Factor Authentication`  
`CSP    Communication System Provider`  
`SDN    Software Defined Networks`  
`GUI    Graphical User Interface`  
`NE     Network Element`  
`MDM    Mobile Device Management`  
```
CRA    Cyber Resilience Act
OS     Operating System
IDP    Identity Provider
VPN    Virtual Private Network
SIEM   Security Information and Event Management Systems
NMS    Network Management System
2FA    Two Factor Authentication
CSP    Communication System Provider
SDN    Software Defined Networks
GUI    Graphical User Interface
NE     Network Element
MDM    Mobile Device Management
```

# 4 Product context

@@ -329,6 +331,7 @@ The affected Service Requesting Users base is small like in:
The main focus of an IoT network is often data collection, whereas the NMS usually visualizes the collected data metrics to the end-user. The NMS-analysis of the data metrics can be automated including the triggering of warnings, alarms, or even actions based on discovered abnormal events. The NMS has limited computational capacities and consumes a low amount of power.

The NMS controls the configuration of the connected devices. As a minimum, the NMS maintains

1. an inventory of devices that are part of the managed network,
1. establishes and maintains a trust-based relation between itself and the device.

@@ -428,7 +431,7 @@ If the actual use case cannot be clearly assigned, the manufacturer shall includ
**Table 4.5.2-1: Mapping of use cases**

| Use case                                              | SRU     | COM     | EXP     | ACL     | ACC                |
|:-----|:-|:-|:-|:-|
| :---------------------------------------------------- | :------ | :------ | :------ | :------ | ------------------ |
| [4.4.1.1 IoT network with monitoring data collection] | SRU-L-0 | COM-L-0 | EXP-L-0 | ACC-L-1 | ACC-L-2 or ACC-L-3 |
| [4.4.1.2 Home network deployment]                     | SRU-L-0 | COM-L-1 | EXP-L-0 | ACL-L-2 | ACC-L-2 or ACC-L-3 |
| [4.4.2.1 Office network]                              | SRU-L-1 | COM-L-2 | EXP-L-0 | ACL-L-2 | ACC-L-2            |
@@ -480,6 +483,7 @@ An NMS can be formed by a compilation or collaboration of different subsystems i
The security functions may be implemented inside one or more of the subsystems that form the NMS. The NMS can thereby be operated by an OS package manager or other systems which also belong to the NMS and are in scope of the present standard.

The NMS documentation shall clarify whether a security requirement is

1. completed fulfilled by the NMS itself,
1. where it relies on support from external services and
1. to which extent it is dependent on an external service.
@@ -518,7 +522,7 @@ The following are non-technical requirements, that shall be implemented by all p
**Table 5.1-1: Generic requirements**

| Requirement     | Assesment                                                                                                     |
|:-|:-----|
| :-------------- | :------------------------------------------------------------------------------------------------------------ |
| **[REQ-GEN-0]** | Technical documentation exists, is available for national MSAs and has product related risk factors declared. |
| **[REQ-GEN-1]** | National MSAs are able to validate the system design comformity without a deployment.                         |

@@ -533,7 +537,7 @@ Note that a container has always an operating system.
**Table 5.1.1-1: Exploitable requirements - 1**

| Requirement         | Objective                                                                                                 |
|:-|:-----|
| :------------------ | :-------------------------------------------------------------------------------------------------------- |
| **[REQ-EXPLOIT-0]** | NMS dependencies to Operating System essential security capabilities are documented.                      |
| **[REQ-EXPLOIT-1]** | Disclosure of new vulnerabilities in the operating system and its dependencies are proactively monitored. |
| **[REQ-EXPLOIT-2]** | Instructions how to handle the Operating System upgrades are provided.                                    |
@@ -548,7 +552,7 @@ More about [High Availability](#53x-high-availability) in its dedicated chapter.
**Table 5.1.1-2: Exploitable requirements - 2**

| Requirement         | Objective                                                                                                             |
|:-|:-----|
| :------------------ | :-------------------------------------------------------------------------------------------------------------------- |
| **[REQ-EXPLOIT-4]** | Product is free of known vulnerabilities at the time it is placed on the market.                                      |
| **[REQ-EXPLOIT-5]** | Disclosure of new vulnerabilities in the application dependencies are proactively monitored.                          |
| **[REQ-EXPLOIT-6]** | Application design makes it possible to upgrade the OS while keeping the set High Availability targets.               |
@@ -580,7 +584,6 @@ Later [Section 5.3 Risk Mitigations](#53-risk-mitigations) combines these genera

Technical requirements:


-   **[REQ-TECH-0]** An network management system shall implement appropriate cryptographic libraries to allow the protection to the requirements of the forseeable use.
-   **[REQ-TECH-1]** The product is shipped without undocumented interfaces.
-   **[REQ-TECH-2]** Any administrative action shall be recorded for audit purposes.
@@ -592,7 +595,7 @@ Technical requirements:
**Table 5.2-1: Technical cybersecurity requirements**

| Requirement      | Assesment                                                                                                    |
|:-|:-----|
| :--------------- | :----------------------------------------------------------------------------------------------------------- |
| **[REQ-TECH-0]** | See [5.2.3 Appropriate cryptographic libraries](#523-appropriate-cryptographic-libraries)                    |
| **[REQ-TECH-1]** | Deployment of a production distribution exposes only documented interfaces.                                  |
| **[REQ-TECH-2]** | Actions are recorded and can not be modified later.                                                          |
@@ -613,7 +616,7 @@ The chosen method shall follow the intent in the CRA by protecting the data tran
**Table 5.2.1-1: Secure channel requirements**

|  **[REQ-TECH-3]** Assesment                  | Details                                                                                    |
|:-|:---|
| :------------------------------------------- | :----------------------------------------------------------------------------------------- |
| Appropriate cryptographic libraries are used | See [5.2.4 Appropriate cryptographic libraries](#524-appropriate-cryptographic-libraries)  |
| Mutual trust                                 | All endpoints in a secure channel can cryptographically verify others.                     |

@@ -706,7 +709,7 @@ Reflecting to [List of Risk Factors](#451-list-of-risk-factors) defined in this
**Table 5.3.2-1: Mitigation requirements**

| Name           | ACC-L-0         | ACC-L-1                | ACC-L-2                  | ACC-L-3                                |
|:-|:-|:-|:-|:-|
| :------------- | :-------------- | :--------------------- | :----------------------- | :------------------------------------- |
| Network        | Air gapped      | Single public endoint  | Multiple endpoints       | Everything else                        |
| [REQ-TECH-0]   | Required        | Required               | Required                 | Required                               |
| [REQ-TECH-1]   | Required        | Required               | Required                 | Required                               |
@@ -749,17 +752,16 @@ Pull style configuration updates:
-   **[REQ-LOG-1]** The write only log or tracing storage is deployed outside of the system deployment context.
-   **[REQ-LOG-2]** The system reports relevant administrative operations forward to an external SIEM system.
-   **[REQ-LOG-3a]** The log file of events shall be protected from unauthorized access, modification,
-   **[REQ-LOG-3b]** be backup-ed,  
-   **[REQ-LOG-3b]** have a active backup scheduled,
-   **[REQ-LOG-3c]** and is confidentiality protected.
-   **[REQ-LOG-4]** SIEM transfer format, field attributes and event descriptions are available as part of the technical documentation.


Manfacturer shall implement logging system features listed in the table below.

**Table 5.3.5-1: Logging requirements**

| Name                  | [EXP-L-0]     | [EXP-L-1]   |
|:-|:-|:-|
| :-------------------- | :------------ | :---------- |
| Entity classification | Undefined     | NIS2 entity |
| [REQ-LOG-0]           | Required      | Required    |
| [REQ-LOG-1]           | Required      | Required    |
@@ -805,7 +807,7 @@ Manfacturer shall implement requirements as listed in the table below.
**Table 5.3.6-1: Monitoring requirements**

| Name                              | [COM-L-0]     | [COM-L-1]   | [COM-L-2]         |  [COM-L-3]  | [6.3.6 Monitoring tests]     |
|:--|:-|:-|:-|:-|:--|
| :-------------------------------- | :------------ | :---------- | :---------------- | :---------- | :--------------------------- |
| Complexity of the managed element | Limited IoT   | Home device | Enterprise router | Basestation |                              |
| [REQ-MON-0]                       | Required      | Required    | Required          | Required    | [6.3.6.0](#6360-req-mon-0)   |
| [REQ-MON-1]                       | Required      | Required    | Required          | Required    | [6.3.6.1](#6360-req-mon-1)   |
@@ -857,7 +859,7 @@ Manfacturer shall implement requirements as listed in the table below.
**Table 5.3.8-1: High availability requirements - 1**

| Name       | ACC-L-0    | ACC-L-1                | ACC-L-2            | ACC-L-3         |
|:-|:-|:-|:-|:-|
| :--------- | :--------- | :--------------------- | :----------------- | :-------------- |
| Network    | Air gapped | Single public endoint  | Multiple endpoints | Everything else |
| [REQ-HA-0] | Required   | Required               | Required           | Required        |
| [REQ-HA-1] | Required   | Required               | Required           | Required        |
@@ -869,7 +871,7 @@ Manfacturer shall implement requirements as listed in the table below.
**Table 5.3.8-2: Mitigation requirements - 2**

| Name                              | SRU-L-0      | SRU-L-1                     | SRU-L-2  |
|:-|:-|:-|:-|
| :-------------------------------- | :----------- | :-------------------------- | :------- |
| Affected Service Requesting Users | Household    | Medium or large enterprise  | CSP      |
| [REQ-HA-0]                        | Required     | Required                    | Required |
| [REQ-HA-1]                        | Not required | Required                    | Required |
@@ -881,7 +883,7 @@ Manfacturer shall implement requirements as listed in the table below.
**Table 5.3.8-3: Mitigation requirements - 3**

| Name                  | [EXP-L-0]      | [EXP-L-1]   | [6.3.8 High availability tests] |
|:-|:-|:-|:--|
| :-------------------- | :------------- | :---------- | :------------------------------ |
| Entity classification | Undefined      | NIS2 entity |                                 |
| [REQ-HA-0]            | Not required   | Required    | [6.3.8.0](#6380-req-ha-0)       |
| [REQ-HA-1]            | Not required   | Required    | [6.3.8.1](#6380-req-ha-1)       |
@@ -1470,7 +1472,7 @@ Matching tests for these requirements are listed in [6.3.8 High availability tes
**Table A-1: Essential requirements mapping**

| CRA requirement                                 | Technical cybersecurity requirements                                                    |
|:-|:--|
| :---------------------------------------------- | :-------------------------------------------------------------------------------------- |
| No known exploitable vulnerabilities            | [5.1.1 No known exploitable vulnerabilities]                                            |
| Secure design, development, production          | [5.1.2 Secure design, development and production], [5.1.3 Product lifecycle management] |
| Secure by default configuration                 | [5.2.4 Appropriate cryptographic libraries]                                             |
@@ -1517,7 +1519,7 @@ Matching tests for these requirements are listed in [6.3.8 High availability tes
**Table A-2: Cybersecurity requirements mapping to sections**

| Section                                                                            |  Content status                   |  Tests status                   |
|:---|:-|:-|
| :--------------------------------------------------------------------------------- | :-------------------------------- | :------------------------------ |
| [5.1 General]                                                                      | will be ammended with new content | todo                            |
| [5.1.1 No known exploitable vulnerabilities]                                       | ready for review                  | todo                            |
| [5.1.2 Secure design, development and production]                                  | todo                              | todo                            |
@@ -1647,7 +1649,7 @@ The manufacturer shall follow the CRAs pricibles of implementing high level of c
**Table C.2.2-1: Threats**

| What             | How?                                                          | More?                        |
|:-|:---|:--|
| :--------------- | :------------------------------------------------------------ | :--------------------------- |
| [CVE-2025-6763]  | Unauthorized configration modification                        |
| [CVE-2024-5245]  | Default Credentials Local Privilege Escalation                | [CVE-2024-5245 PoC]          |
| CVE-2025-46274   | Hard-coded credentials                                        |
@@ -1822,7 +1824,7 @@ Other Union legislation may be applicable to the product(s) falling within the s
The \"Change history/Change request (history)\" annex shall be included in every revised or amended harmonised standard and shall contain information concerning significant changes that have been introduced by it. It shall be presented as a table.

| Date            | Version | Information about changes                 |
|:-|:-|:-|
| :-------------- | :------ | :---------------------------------------- |
| &lt;Month year> | <#>     | &lt;Changes made are listed in this cell> |
|                 |         |                                           |
|                 |         |                                           |
@@ -1833,6 +1835,6 @@ The \"Change history/Change request (history)\" annex shall be included in every
The following table will automatically be filled in by the ETSI Secretariat.

| Document History |      |                |
|:-|:-|:-|
| :--------------- | :--- | :------------- |
| Version          | Date | Milestone      |
| <Month year>     | <#>  | <Changes made> |