Commit 98d6b6c2 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Editorial changes to 5.4 Secure by default configuration

parent af860acf
Loading
Loading
Loading
Loading
+9 −8
Original line number Diff line number Diff line
@@ -1116,12 +1116,13 @@ If the deliverable contains or requires an operating system the operating system
Depending on the chosen delivery method, the maintenance of the operating system can be provided by the customer of the product.
Note that a container has always an operating system.

* **KEV_EXPLOIT-1** If automateable vulnerability scanners are available the product shall satisfy the following with respect to the most comprehensive of such scanners.
* **KEV_EXPLOIT-1** If automateable vulnerability scanners are available the product shall satisfy the following with respect to the most comprehensive of such scanners:
  * The product shall have no known exploitable vulnerabilities discovered by scans.
  * For each identified exploitable vulnerability, the product shall have the risk mitigated.
  * The used vulnerability scanner shall be fit for the purpose in detail, method and depth.

Recognising that there may be vulnerabilities discovered between the time that a product is placed on the market and the time of that product's first use, and that the product should be free from known exploitable vulnerabilities both when first made available and when first used by the system user.
Recognising that there may be vulnerabilities discovered between the time that a product is placed on the market and the time of that product's first use, and that the product should be free from known exploitable vulnerabilities both when first made available and when first used by the product user.
The period of the product lifecycle, which is after the release, is addressed in [5.5 Security updates](#55-security-updates) section.

## 5.4 Secure by default configuration

@@ -1890,8 +1891,8 @@ Verify that:

**Preparation:**

* [DESIGN] Product documentation identifying elements contained in the product (elements may include software, firmware, or hardware elements, as applicable).
* [INVENTORY] component inventory, bill of materials, or equivalent software identification information, including version and patch-level information where available.
* Product documentation identifying elements contained in the product (elements may include software, firmware, or hardware elements, as applicable).
* Component inventory, bill of materials, or equivalent software identification information, including version and patch-level information where available.
* Access to the product, or to relevant components such as binaries, packages, images, firmware, containers, or file systems, sufficient to perform vulnerability scanning where technically feasible.
* Vulnerability scanning tools and associated vulnerability databases suitable for identifying candidate vulnerabilities in the product.
* Access to recognized public vulnerability sources:
@@ -1916,10 +1917,10 @@ Verify that:

**Supporting Evidence:**

* [SCAN] Vulnerability scanning results, including the tools and vulnerability databases used with snapshot date information.
* [ADVISORY] Recognized public vulnerability sources, vendor advisories, and product identification information used in the assessment.
* [ANALYSIS] Vulnerability assessment records and conclusions produced in accordance with prEN 40000-1-3 [X].
* [GUIDANCE] Product user guidance relied upon to prevent exploitation, where applicable.
* Vulnerability scanning results, including the tools and vulnerability databases used with snapshot date information.
* Recognized public vulnerability sources, vendor advisories, and product identification information used in the assessment.
* Vulnerability assessment records and conclusions produced in accordance with prEN 40000-1-3 [X].
* Product user guidance relied upon to prevent exploitation, where applicable.

## 6.4 Secure by default configuration