Commit c6ae6395 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Added assumptions to Annex C

parent 948daeef
Loading
Loading
Loading
Loading
+14 −0
Original line number Diff line number Diff line
@@ -525,6 +525,20 @@ The technical requirements of the present document apply under the environmental

> List assumptions that are relevant to the risk analysis for these threats. Everything is hackable if you try hard enough. What kinds of threats are in and out of scope? What are you assuming is the sophistication of attack? Relate to use cases.

- Proper platform

  - **Rationale:** A network management system requires a trustworthy operating system to perform its functions.
  - [A-PP-L-1]: The operating system is assumed to be trustworthy.
  - [A-PP-L-2]: The operating system provides and enforces process isolation

- Proper administrator

  - **Rationale:** A network management system requires effective administration to perform its functions.
  - [A-PA-L-1]: The administrator is assumed to be trustworthy.
  - [A-PA-L-2]: The administrator is limited to protect against accidental misconfiguration.
  - [A-PA-L-3]: The administrator is severely limited to protect against intentional misconfiguration.
  - [A-PA-L-4]: The administrator actions can be traced in case of accidental or intentional misconfiguration.

- Not being attacked by a state actor
- Not using sophisticated or expensive hardware snooping techniques
- No secret hardware backdoors