@@ -136,6 +136,10 @@ The following referenced documents may be useful in implementing an ETSI deliver
<spanid="_ref_i.7"></span><aname="_ref_i.6">[i.7]</a> prEN 40000-1-4: "Cybersecurity requirements for products with digital elements – Part 1-4: Security controls – Generic security requirements”
<mark>Below this line are reference, that needs to be checked, if needed still.</mark>
<spanid="_ref_i.8"></span><aname="_ref_i_x">[i.8]</a> ENISA April 2025 (Version 2.0) "Agreed Cryptographic Mechanisms"
<spanid="_ref_i.2"></span><aname="_ref_i.2">[i.2]</a> ETSI EN 304 XXX IAM (CEN/TC 224 WG 17 output)
<spanid="_ref_i.3"></span><aname="_ref_i.3">[i.3]</a> ETSI EN 304 620 "Virtual Private Networks (VPNs)"
@@ -162,13 +166,10 @@ The following referenced documents may be useful in implementing an ETSI deliver
<spanid="_ref_i.17"></span><aname="_ref_i.17">[i.17]</a> Example source for DDoS related threat reports https://radar.cloudflare.com/reports
<spanid="_ref_i.2"></span><aname="_ref_i.2">[i.2tk5]</a> ETSI EN 304 XXX IAM (CEN/TC 224 WG 17 output)
<spanid="_ref_i.6"></span><aname="_ref_i.6">[i.6tk9]</a> ETSI EN 304 624 "PKIs and certificate issuance software"
<spanid="_ref_i.9"></span><aname="_ref_i.9">[i.9tk12]</a> ETSI EN 304 642 "Cybersecurity Requirements for Telecommunication Systems"
<spanid="_ref_i.x"></span><aname="_ref_i_x">[i.x]</a> ENISA April 2025 (Version 2.0) "Agreed Cryptographic Mechanisms"
# 3 Definition of terms, symbols and abbreviations
Network management systems are commonly deployed using centralized management services that provide command, control, monitoring, and administration functions.
Network management systems are commonly deployed using centralised management services that provide command, control, monitoring, and administration functions.
Depending on the design and autonomy of the managed elements, some elements may continue limited operation when connectivity to the network management system is unavailable.
In larger deployments, network design and operational parameters can affect the reliability and scalability of connectivity between managed elements and the network management system.
@@ -979,16 +980,16 @@ Beyond collecting data from connected devices and preparing data metrics, the NM
The ICT Element management is an enterprise-focused system to control and manage the configuration of the connected enterprise application on the ICT Elements.
An ICT Element can encompass anything from routers, modems, switches up to mobile devices, tablets, smart phones, laptops, desktop PCs to servers.
The use case describes a system that provides centralized governance of the enterprise application running on the ICT Elements within the scope of an organization.
The use case describes a system that provides centralised governance of the enterprise application running on the ICT Elements within the scope of an organization.
ICT device management is in general subject to enterprises or larger organizations that equip their employees with the essential ICT elements they work with.
The users usually do not have full administration rights and are restricted to the application level to manage personal look and feel.
Due to the broad functionality of the ICT Elements, the controls need also to be strongly extended, compared with the IoT use case, to ensure the centralized governance by the enterprise for the related application is maintained.
Due to the broad functionality of the ICT Elements, the controls need also to be strongly extended, compared with the IoT use case, to ensure the centralised governance by the enterprise for the related application is maintained.
That can be characterized as follows:
* Provision of preconfigured ICT elements or enterprise applications to the employees
*Centralized ICT element or enterprise application update management
*centralised ICT element or enterprise application update management
* Trust establishment between the ICT elements, or the enterprise application, other communicating entities and the NMS, by the NMS
* The NMS controls and sets the ICT element and the enterprise application configuration settings to manage:
* The connectivity of the managed ICT elements and the enterprise application among each other, like VPN configuration
@@ -1245,7 +1246,7 @@ Therefore, application of updates needs to be performed in a manner that maintai
***SU_UPDATES-7:** The product shall provide a way for the system user to postpone or re-schedule the application update.
The requirements **SU_UPDATES-8** to **13** are conditional due to different operative management and ownership models.
A cellphone that is connected to a corporate inventory management often has its own update manager, and the device does not rely on the centralized control.
A cellphone that is connected to a corporate inventory management often has its own update manager, and the device does not rely on the centralised control.
Similarly in a modern cluster deployment, the application can not update itself, as the control is in the cluster, which makes the provisioning, scheduling and network shaping decisions for all applications running in the same context.
***SU_UPDATES-8:** If the product supports intentional rollback, invoking action shall require explicit authorisation and an auditable event is emitted with rollback metadata.
@@ -1345,17 +1346,16 @@ As the product is delivered without known exploitable vulnerabilities, those leg
***CON_CRYPTO-1** The product’s default configuration shall only use cryptographic mechanisms that meet at least one of the following criteria:
1. ACM-listed: the cryptographic mechanism is listed in the ECCG Agreed Cryptographic Mechanisms (ACM) catalogue [reference].
2. ACM-extended: the cryptographic mechanism is not listed in the ECCG Agreed Cryptographic Mechanisms (ACM) catalogue [reference] and meets at least one of the following conditions:
1. ACM-listed: the cryptographic mechanism is listed in the ECCG Agreed Cryptographic Mechanisms (ACM) catalogue \[i.8\].
2. ACM-extended: the cryptographic mechanism is not listed in the ECCG Agreed Cryptographic Mechanisms (ACM) catalogue \[i.8\] and meets at least one of the following conditions:
1. the cryptographic mechanism is listed in clause K.3.2 as an ACM-extended cryptographic mechanism for the specific product function(s);
2. where the cryptographic mechanism is not listed in clause K.3.2, the cryptographic mechanism meets all the following criteria:
1. the cryptographic mechanism, or where applicable the ACM-listed cryptographic mechanism on which it is based, is not deprecated per the ECCG Agreed Cryptographic Mechanisms (ACM) catalogue [reference];
2. the cryptographic mechanism has been specified, developed or maintained through a transparent process by a recognised European, international or sector-specific standards development organisation, or by an industry specification organisation accountable for the relevant specification, including <mark>[list of organisations]</mark>; or the cryptographic mechanism is listed as suitable in a publicly available cryptographic catalogue maintained by a recognised national or governmental cybersecurity authority, where the catalogue is maintained under a documented revision and retirement process, including <mark>[list of catalogues]</mark>;
1. the cryptographic mechanism, or where applicable the ACM-listed cryptographic mechanism on which it is based, is not deprecated per the ECCG Agreed Cryptographic Mechanisms (ACM) catalogue \[i.8\];
2. the cryptographic mechanism has been specified, developed or maintained through a transparent process by a recognised European, international or sector-specific standards development organisation, or by an industry specification organisation accountable for the relevant specification, including CEN, CENELEC, ETSI, ISO, IEC, ISO/IEC JTC 1, IETF, IEEE, ITU-T, NIST, 3GPP, O-RAN Alliance, BSI, ACN, C2SP; or the cryptographic mechanism is listed as suitable in a publicly available cryptographic catalogue maintained by a recognised national or governmental cybersecurity authority, where the catalogue is maintained under a documented revision and retirement process, including BSI TR-02102-1, BSI TR-02102-2, BSI TR-02102-3 and BSI TR-02102-4;
3. the cryptographic mechanism is described in a valid, publicly available and uniquely referenceable specification;
4. the cryptographic properties of the cryptographic mechanism are known;
5. no known weakness affects the cryptographic mechanism in a way that affects its cryptographic properties;
6. the cryptographic mechanism is required for a specific set of product functions;
7.<mark>[any additional criteria specified by the vertical standard, where applicable]</mark>.
3. Interoperability-based: the cryptographic mechanism is listed in clause K.4.2 as an interoperability-based cryptographic mechanism for specific product function(s) and external specification(s) or external requirement(s).
***CON_CRYPTO-2** To prevent rollback or downgrade [i.10] the product shall:
* enforce a monotonic policy/configuration version (or equivalent mechanism);
@@ -2061,8 +2061,6 @@ Verify that:
### 6.5.3 SU_UPDATE-3
<mark>Weak text</mark>
**Preparation:** Program a test source providing an authentic and integrity correct update package.<br/>
**Activities:**
@@ -3976,8 +3974,6 @@ Outcomes:
# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 - the Cyber Resilience Act
<mark>Editor's Note: Even if informative, this Annex is mandatory in Harmonised Standards.</mark>
The present document has been prepared in response to the Commission's standardisation request C(2025)618 [\[i.3\]](#_ref_i.3) to provide, in addition to its other uses, one voluntary means of conforming to the essential requirements of Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2) known as the Cyber Resilience Act (CRA).
Once the present document is cited in the Official Journal of the European Union under Regulation (EU) 2024/2847 [\[i.1\]](#_ref_i.1), conformance with the normative clauses of the present document given in the tables in Annex A confers, to products with digital elements in the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Regulation and associated EFTA regulations.
@@ -4067,8 +4063,6 @@ Once the present document is cited in the Official Journal of the European Union
**Clause(s) of the present document** Identification of clause(s) defining the requirement in the present document unless another document is referenced explicitly.
<mark>Editor’s Note: When referencing clause(s) of the present document to evidence fulfilment of essential requirements, ensure full coverage of the essential requirement with regard to all elements of the legal definition thereof. To this end, validate referenced content against the definition after the fact to ensure no angle has been missed.</mark>
Presumption of conformity stays valid only as long as a reference to the present document is maintained in the list published in the Official Journal of the European Union. Users of the present document should consult frequently the latest list published in the Official Journal of the European Union.
Other Union legislation may be applicable to the product(s) falling within the scope of the present document.