Commit cc88b543 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Removed broken references

parent b6c927e8
Loading
Loading
Loading
Loading
+6 −6
Original line number Diff line number Diff line
@@ -530,7 +530,7 @@ Considering these and similar scenarios, assuming that the lower level network t
An important system like the product in this document needs multiple layers of defence.

When management traffic is classified to be Application level traffic, there is no reason to not use encryption with the served interfaces.
This is noted later in **CYB_OPS-*** under [5.2.1 Operative environment](#521-operative-environment).
This is noted later in **CYB_OPS-***.

### 4.2.4 Inventory, device and subjects management

@@ -1630,7 +1630,7 @@ For **high** risk:
* everything in medium risk, and
* **IM_SEGMENT-3** Available interfaces shall accept traffic only from a dedicated virtually or physically connected subnet.

> NOTE: In default configuration [5.6 Authentication and access control](#56-authentication-and-access-control) applies to all interfaces regardless of the connectivity.
> NOTE: In default configuration applies to all interfaces regardless of the connectivity.

> NOTE: The requirement **CYB_OPS-2** classifies management traffic to be Application level traffic making the low level OT designs incompatible with this document.

@@ -5210,7 +5210,7 @@ Threats to secure update during installation & execution:
* Rollback protections bypass
* Loss of availability if update fails or is interrupted

Therefore, application of updates needs to be performed in a manner that maintains the integrity of the software state and, where relevant, supports the availability objectives defined for the product keeping the system within the set [5.3.8 High Availability](#538-high-availability) targets.
Therefore, application of updates needs to be performed in a manner that maintains the integrity of the software state and, where relevant, supports the availability objectives defined for the product keeping the system within the set High Availability targets.

### **SU_UPDATES-7** to **SU_UPDATES-13**

@@ -5230,7 +5230,7 @@ The model can be complex, and there can be multiple different overlapping mechan

While the requirement calls for active checking, in combination with **AAC_AUTH-4:** the wording leaves room to implement a fluent GUI experience when viewing the content and performing privileged actions are separated.

Credential rotation addressed by **INT_ROTATE-1** in [5.8.2 Cryptographic key initialisation and rotation](#582-cryptographic-key-intialisation-and-rotation), is one of the key elements that enable organisations to build resilience in a compromised network.
Credential rotation addressed by **INT_ROTATE-1** is one of the key elements that enable organisations to build resilience in a compromised network.
The rotation can replace keys or tokens to limit exposure from compromised credentials.
It can be built on top of existing authority structures, or it can re-run some parts of the element initialisation procedures.
How the retake of the authority is implemented is between the product and the element.
@@ -5329,9 +5329,9 @@ For a telco environment, this means a slightly more complex an more performance
In many product deployments, privileged users manage monitoring tasks also with the analysis of product logging records.
Especially when there are forensic demands, comprehensive and detailed logging becomes a larger challenge.

The logging requirements in subclause [5.14.1 Logging](#5141-logging) define baseline event recording and additional protections for retention, integrity, backup, and external forwarding.
The logging requirements define baseline event recording and additional protections for retention, integrity, backup, and external forwarding.

The metrics requirements in subclause [5.14.2 Metrics](#5142-metrics) support security monitoring, operational visibility, fault detection, and verification of system behaviour.
The metrics requirements support security monitoring, operational visibility, fault detection, and verification of system behaviour.
Fulfilment of these requirements is essential for all products in all use cases and all risk levels.
Breaches can not be detected, if an attacker can hide its existence.