Commit af73d30f authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Combined NIS2 important and essential entities

parent a54c8528
Loading
Loading
Loading
Loading
+12 −18
Original line number Diff line number Diff line
@@ -370,10 +370,6 @@ There can be multple devices in the same network, and the NMS provides supportin

![Office network](./media/2025-08-10_office.drawio.png)

#### 4.4.2.2 Waste management

<mark>Draw somethign nice</mark>

#### 4.4.2.3 Telecom network

![Telecom network](./media/2025-08-10_telco.drawio.png)
@@ -410,10 +406,9 @@ The risk factors identified by the risk assessment in Annex C are grouped into r

-   Security expectations of intented network segment operation

    -   **Rationale**: NIS2 identifies entities that require higher level of protection
    -   **Rationale**: NIS2 identifies entities that require higher level of protection. The important and essential classificatoins are combined as the NIS2 does't make additional security requirements based on classification.
    -   **[EXP-L-0]** Undefined
    -   **[EXP-L-1]** NIS2 important entity
    -   **[EXP-L-2]** NIS2 critical entity
    -   **[EXP-L-1]** NIS2 important or essential entity

-   Access to network used for communication between elements
    -   **[ACC-L-0]** Network physically isolated from public networks with strong physical access control procedures
@@ -434,8 +429,7 @@ In case of overlap in the requirements, a stronger and more secure option shall
| [4.4.1.1 IoT network with monitoring data collection] | SRU-L-0 | COM-L-0 | EXP-L-0 | ACC-L-1 |
| [4.4.1.2 Home network deployment]                     | SRU-L-0 | COM-L-1 | EXP-L-0 | ACL-L-2 |
| [4.4.2.1 Office network]                              | SRU-L-1 | COM-L-2 | EXP-L-0 | ACL-L-2 |
| [4.4.2.2 Waste management]                            | SRU-L-1 | COM-L-2 | EXP-L-1 | ACL-L-2 |
| [4.4.2.3 Telecom network]                             | SRU-L-2 | COM-L-3 | EXP-L-2 | ACL-L-3 |
| [4.4.2.3 Telecom network]                             | SRU-L-2 | COM-L-3 | EXP-L-1 | ACL-L-3 |

[4.4.1.1 IoT network with monitoring data collection]: #4411-iot-network-with-monitoring-data-collection
[4.4.1.2 Home network deployment]: #4412-home-network-deployment
@@ -671,18 +665,18 @@ Unwanted traffic in the interfaces can cause a denial of service from the manage
-   **[LOG-3]** NMS emits SIEM events from relevant changes.
-   **[LOG-4]** SIEM transfer format, field attributes and event descriptions are available as part of the technical documentation.

| Name                  | [EXP-L-0]     | [EXP-L-1]      | [EXP-L-2]      |
| --------------------- | ------------- | -------------- | -------------- |
| Entity classification | Undefined     | NIS2 important |  NIS2 critical |
| [LOG-0]               | Required      | Required       | Required       |
| [LOG-1]               | Required      | Required       | Required       |
| [LOG-2]               | Not required  | Not required   | Required       |
| [LOG-3]               | Not required  | Required       | Required       |
| [LOG-4]               | Not required  | Required       | Required       |
| Name                  | [EXP-L-0]     | [EXP-L-1]   |
| --------------------- | ------------- | ----------- |
| Entity classification | Undefined     | NIS2 entity |
| [LOG-0]               | Required      | Required    |
| [LOG-1]               | Required      | Required    |
| [LOG-2]               | Not required  | Required    |
| [LOG-3]               | Not required  | Required    |
| [LOG-4]               | Not required  | Required    |

| Requirement | Assesment                                                                             |
| ----------- | ------------------------------------------------------------------------------------- |
| [LOG-0]     | All system clocks are synchronized into a NTP server or similar.                      |
| [LOG-0]     | All system clocks are synchronized to a NTP server or similar.                        |
| [LOG-1]     | From the process, it is impossible to overwrite the log output.                       |
| [LOG-2]     | Technical documentation specifies how to integrate into an external logging system.   |
| [LOG-3]     | Detailed information of all emitted events is available.                              |