Commit d6ef0d8a authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Moved assets to new structure

parent 74e31d88
Loading
Loading
Loading
Loading
+0 −43
Original line number Diff line number Diff line
@@ -189,51 +189,8 @@ To be able to map the product requirements applicability:

NMS protects systems that are relying on network connectivity to perform its daily operations.

**Business continuity**

-   market information
-   business-critical processes
    -   manufacturing
    -   finances
-   compliance evidence if form of logs and reports

**Incident response capability**

-   ability to detect, diagnose, and remediate outages

**Network configuration**

- network configuration
- network inventory
- network topology
- network segmentation policies
- firewall rules

**Connected devices**

- management traffic
- access to the management interface
- connected devices updates, patches
- CORBA access, grcp
- keys can be generated or imported through the key management modules

### C.2.1.1 Data assets

The stored data depends on what functions the NMS has available and what the intend use is.
The stored data can be, but is not limited to:

-   System audit data
    -   authentication data
    -   syslogs
-   cryptographic data like encryption keys
-   Backups
-   Device monitoring data
-   Sensitive monitoring data
    -   NetFlow information
    -   Packet captures
    -   Protocol analysis information
-   Network configuration data

## C.2.2 Threats

> Based on the assets, what are the threats during:
+25 −2
Original line number Diff line number Diff line
@@ -4018,13 +4018,36 @@ Attack vectors that are the responsibility of the network management system:

## B.1 Asets

**Business continuity**

* Market information
* Business-critical processes
  * Manufacturing
  * Finances
* Compliance evidence if form of logs and reports

**Incident response capability**

* Ability to detect, diagnose, and remediate outages

**Network configuration**

* Network configuration data
* Network metrics data
* Network inventory
* Network topology
* Network segmentation policies
* Network and device secrets
* Device inventory
* Network metrics data
* Firewall rules
* User register
* User secrets

**Connected devices**

* Management traffic
* Access to the device management interface
* Connected devices updates, patches

## B.2 Risk Factors

This assessment provides a risk factors for the intended purpose and foreseeable uses of the product.