@@ -198,47 +198,27 @@ The following referenced documents may be useful in implementing an ETSI deliver
For the purposes of the present document, the terms given in Regulation (EU) 2024/2847 [\[i.1\]](#_ref_i.1), prEN 40000-1-1 [\[i.4\]](#_ref_i.4) and the following apply:
<mark>Editor's Note: A definition of term should be such that it can replace the term in context. Any additional information shall be given only in the form of examples or notes. (see ETSI Directives section EDRs, clause 2.11.1).</mark>
<mark>Editor's Note: Proposal to put together a common term sheet for all verticals developed in CYBER-EUSR.</mark>
<mark>Editor’s Note: For ease of reading, it is possible to quote the definitions of Regulation (EU) 2024/2847. Use of quotation marks is mandatory in such a case.</mark>
<mark>Editor’s Note: The standard should not do legal interpretation by defining some key legal concepts of Regulation (EU) 2024/2847. Notably, the standard should not define “core functionality” or “due diligence”.</mark>
1.**Operating System (OS):** software product that provides an abstract interface to the underlying hardware and that controls the execution of software
1.**Identity Provider (IDP):** system maintaining identity information
1.**Service Requesting Users (<span name="_term_.SRU">SRU</span>):** users relying on the correct functioning of the network element
1.**user:** person having the credentials to login to the NMS to operate administrative actions to control and maintain the managed element
1.**machine user:** virtual user used to access the system programming interfaces
1.**component:** software or hardware intended for integration into an electronic information system
1.**Application Programming Interface (API):** interface used to communicate with the running program
1.**log**: record of an operational event
1.**trace**: record of a system status with all relevant data that can be gathered
2.**Identity Provider (IDP):** system maintaining identity information
3.**Service Requesting Users (<span name="_term_.SRU">SRU</span>):** users relying on the correct functioning of the network element
4.**user:** person having the credentials to login to the NMS to operate administrative actions to control and maintain the managed element
5.**machine user:** virtual user used to access the system programming interfaces
6.**component:** software or hardware intended for integration into an electronic information system
7.**Application Programming Interface (API):** interface used to communicate with the running program
8.**log**: record of an operational event
9.**trace**: record of a system status with all relevant data that can be gathered
## 3.2 Symbols
<mark> Editor's Note: choose one of the three following lines, whichever applies most appropriately. Replace ... with your reference.</mark>
For the purposes of the present document, the following symbols apply:
For the purposes of the present document, the symbols given in ... apply:
For the purposes of the present document, the symbols given in ... and the following apply:
<mark>Add in the symbols used in the architecture drawings?</mark>
## 3.3 Abbreviations
<mark> Editor's Note: choose one of the three following lines, whichever applies most appropriately. Replace ... with your reference.</mark>
For the purposes of the present document, the following abbreviations apply:
For the purposes of the present document, the abbreviations given in ... apply:
For the purposes of the present document, the abbreviations given in ... and the following apply:
<mark>Editor's Note: The following is a list of abbreviations used in some of the CRA vertical standards. It is not complete yet.</mark>
<mark>Editor's Note: Please only keep the abbreviations that are used in the present document and avoid using the same abbreviation with different meaning in the CRA vertical standards.</mark>
For the purposes of the present document, the abbreviations given in <mark>... do we refer PT1?</mark> and the following apply:
`ACM Agreed Cryptographic Mechanisms`
@@ -308,13 +288,15 @@ For the purposes of the present document, the abbreviations given in ... and the
The product context for network managment systems is detailed in the following clause. Product context is descriptive, and clause 4 does not contain normative requirements.
Instead it is a tool for the manufacturer of NMS products that describes NMS products in greater detail and provides information reagarding the functions, architecture, operational environment, distrubution of security functions, and common use cases for network managment systems.
The information below is provided as a tool for manufactuerers of NMS products that wish to conform to this standard and offers insight into how a specific product fits within the scope of this standard and which of the technical cybersecurity requirements detailed in clause 5 apply to a specific product.
The information below is provided as a tool for manufactuerers of NMS products that wish to conform to this standard and offers insight into how a specific product fits within the scope of this standard and which of the technical cybersecurity requirements detailed in [clause 5](#5-technical-requirements-for-the-products) apply to a specific product.
## 4.0 Introduction
Network management systems consist of a variety of software and hardware products that enable thier user to oversee a network of connected devices.
This generally includes configuration, maintenance, and monitoring of the user's network so that it reamins functional and connected.
Beyond this most basic purpose and description, NMS products and thier implementations vary widely.
The information below offers an overview of NMS within the scope of this standard and culminates in descriptive use cases that may assist manufacturers as models for determining the appropriate treatment of risk and mitigations necessary to apply to similar products.