@@ -427,6 +427,12 @@ The OE for [SRU-L-2] shall ensure:
• Physical access control to ensure access by authorized staff only
• Authorized staff shall be trained and qualified on the NMS, trusted, operate without malicious intent and act according the NMS user guidelines
> A block from IAM
As necessary functions as identification and authorisation are, a NMS can still serve traffic without perfroming an identification routine as long as that traffic is authorised in another way.
For example, residential routers are often configured in a way that physical access to a local port is sufficient to identify a Service Requesting User (SRU) authorisation is provided by proximity and a user with physical access becomes the beneficiary of the provisioned configuration.
This does not mean that every access channel should provide authorisation with physical access. A managed device can have a configuration port, a management API, a firmware update channel, and even a debugging interface, all of them classified as privileged and requiring complex authorisation depending on the device, and its use.