Commit cf6cf445 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Editorial formatting changes

parent 77c21717
Loading
Loading
Loading
Loading
+18 −3
Original line number Diff line number Diff line
@@ -1375,6 +1375,7 @@ For **low** risk:

For **medium** risk:

* everything in low risk, and
* **CYB_GENERAL-4** In the context of key management and accepting new elements to the management context the product shall support:
  1. initialisation of trust in a greenfield deployment, and in the connected element management;
  2. accepting managed elements into the network based on that trust;
@@ -1382,6 +1383,8 @@ For **medium** risk:

For **high** risk:

* everything in low risk, and
* everything in medium risk, and
* **CYB_GENERAL-5** The product shall provide functionality to replace user accessible and controlled cryptographic keys.
* **CYB_GENERAL-6** The product shall clearly indicate the purpose and usage of keys that are not user accessible, where present.
* **CYB_GENERAL-7** The product shall record all system time drift corrections as monitoring events.
@@ -1584,11 +1587,14 @@ For **low** risk:

For **medium** risk:

* everything in low risk, and
* **AP_HA-3** The product shall tolerate loss of external resources within the limits of the defined availability.
* **AP_HA-4** The product shall minimise the impact to other systems when anomalies occur.

For **high** risk:

* everything in low risk, and
* everything in medium risk, and
* **AP_HA-5** The product shall implement coordinated brute‑force and overload protection mechanisms that not only detect excessive authentication attempts or inbound traffic surges, but also enforce active mitigation actions, including at minimum
  1. temporary IP blocking, and
  2. message buffering, and
@@ -1608,20 +1614,23 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P

### 5.11.1 Network segmentation

**Low**:
For **low** risk:

* **IM_SEGMENT-1** The product shall support network segmentation for management traffic where applicable.

**Medium**:
For **medium** risk:

* everything in low risk, and
* **IM_SEGMENT-2** Available management APIs shall accept traffic only from reasonably limited known sources.

> EXAMPLE: A reasonably limited known source would be RFC 1918 [8] private subnet.

> NOTE: The requirement **IM_SEGMENT-2** is designed to be combined with **EMM_ROUTE-2** to reach the required level of protection.

**High**:
For **high** risk:

* everything in low risk, and
* everything in medium risk, and
* **IM_SEGMENT-3** Available interfaces shall accept traffic only from a dedicated virtually or physically connected subnet.

> NOTE: In default configuration [5.6 Authentication and access control](#56-authentication-and-access-control) applies to all interfaces regardless of the connectivity.
@@ -1648,10 +1657,13 @@ For **low** risk:

For **medium** risk:

* everything in low risk, and
* **EMM_ROUTE-2** The product shall only permit traffic that is validated and explicitly authorized to transit the management connection.

For **high** risk:

* everything in low risk, and
* everything in medium risk, and
* **EMM_ROUTE-3** The product shall emit an auditable event from out-of-place traffic.

## 5.14 Monitoring
@@ -1701,11 +1713,14 @@ For **low** risk:

For **medium** risk:

* everything in low risk, and
* **MON_LOG-8:** The product shall actively schedule backups for log information.
* **MON_LOG-9:** The product shall maintain tamper-evident audit logs.

For **high** risk:

* everything in low risk, and
* everything in medium risk, and
* **MON_LOG-10** The product shall support forwarding of relevant administrative events to an external logging or SIEM system.
* **MON_LOG-11** The product shall produce logs, SIEM event data transfer format, field attributes and event descriptions in a machine readable format.
* **MON_LOG-12** The product shall export logs as data artifacts that preserve essential fields, at minimum: