@@ -190,35 +190,8 @@ For the purposes of the present document, the following abbreviations apply:
## 4.1 General
> NOTE: This section's structure is built upon CEN/CLC JTC13 PT01's deliverable and might require restructuring based on its progress.
## 4.3 Product overview and architecture
Network management systems are commonly deployed using centralized management services that provide command, control, monitoring, and administration functions.
Depending on the design and autonomy of the managed elements, some elements may continue limited operation when connectivity to the network management system is unavailable.
In larger deployments, network design and operational parameters can affect the reliability and scalability of connectivity between managed elements and the network management system.

**Figure 4.3-1: Product overview and architecture**
Network management systems are operated by users or by programs that interface with an API. These programs can be internal or external to the system depending on the product design and deployment context.
The system is often accessed with a browser using an identity outside of the installation context.
Identity Provider (IdP) can be used as base for the users identity.
In an enterprise setting, or equivalent, the high number of users and the volume of role changes has lead to adoption of dedicated identity management platforms.
The system typically runs on hardware and software components that provide the necessary operating environment and network connectivity.
The Operating System can be part of the deliverable and hense, part of the product.
The OS best practices and requirements are defined outside of this document.
Where relevant to the deployment context, the NMS may interface with external services such as identity, cryptographic, logging, or event management systems, though cybersecurity requirements of these systems, even if integrated into the NMS product, are not addressed by this standard.
The primary function of an NMS is to monitor, configure, administer, or otherwise manage connected network elements.
More about assets in [Annex C.1 Assets](#c1-assets) and [Annex C.2 Data](#c11-data).
## 4.5 Risk Factors
For each NMS placed on the market, the manufacturer shall develop a threat model and risk profile of the foreseeable use of the NMS, and shall consider the interplay between:
@@ -273,6 +273,31 @@ The information below offers an overview of NMS within the scope of this standar
<mark>Editor’s Note: The diagram(s) shall be clearly labeled and accompanied by a short description of the main flows and components.</mark>
Network management systems are commonly deployed using centralized management services that provide command, control, monitoring, and administration functions.
Depending on the design and autonomy of the managed elements, some elements may continue limited operation when connectivity to the network management system is unavailable.
In larger deployments, network design and operational parameters can affect the reliability and scalability of connectivity between managed elements and the network management system.

**Figure 4.3-1: Product overview and architecture**
Network management systems are operated by users or by programs that interface with an API. These programs can be internal or external to the system depending on the product design and deployment context.
The system is often accessed with a browser using an identity outside of the installation context.
Identity Provider (IdP) can be used as base for the users identity.
In an enterprise setting, or equivalent, the high number of users and the volume of role changes has lead to adoption of dedicated identity management platforms.
The system typically runs on hardware and software components that provide the necessary operating environment and network connectivity.
The Operating System can be part of the deliverable and hense, part of the product.
The OS best practices and requirements are defined outside of this document.
Where relevant to the deployment context, the NMS may interface with external services such as identity, cryptographic, logging, or event management systems, though cybersecurity requirements of these systems, even if integrated into the NMS product, are not addressed by this standard.
The primary function of an NMS is to monitor, configure, administer, or otherwise manage connected network elements.
More about assets in [Annex C.1 Assets](#c1-assets) and [Annex C.2 Data](#c11-data).
### 4.2.x Distributed element and deployment design