@@ -391,49 +391,134 @@ For each NMS placed on the market, the manufacturer shall develop a threat model
The security profile requirements reflects the intented deployment of the NMS.
The risk is combination of likelihood and impact.
Each risk factor has instructions when the product should be evaluated in high or low in the respected categories.
The end result is a three tier low-medium-high evaluation of that given risk factor.
A set of risk factors is used to determine what requirements apply to the product in the later section [5 Requirements specifications](#5-requirements-specifications).
**Table 4.5-1: Determining risk level**
| Likelihood / impact | Low | High |
| ------------------- | ------ | ------ |
| Low | Low | Medium |
| High | Medium | High |
### 4.5.1 List of Risk Factors
The risk factors identified by the risk assessment in Annex C are grouped into risk categories and assigned unique identifiers below.
- Number of affected Service Requesting Users [<ahref="#_term_.SRU">SRU</a>]
#### 4.5.1.1 Service requesting users
Number of affected Service Requesting Users [<ahref="#_term_.SRU">SRU</a>]
**Key:** [SRU]<br/>
**Rationale:** the affected user base should be accounted for in the risk definition
For **likelihood** select **low**, if:
- well defined trafic
- small ammount of different traffic classes like IoT network data collection and software updates
- the SRUs are other devices with well-known communication needs
For **likelihood** select **high**, if:
- arbitary traffic
- serving human users with possible various devices like laptops and mobile phones
For **impact** select **low**, if:
- single household or a small business, small ammount of SRUs
For **impact** select **high**, if:
- larger business with multiple sites connected to the same internal network structure
- public telecommunication network providers, Internet service providers, large amount of SRUs
[SRU]:#4511-service-requesting-users
#### 4.5.1.2 Complexity of managed network element implementation
**Key:** [Complexity]<br/>
For **likelihood** select **low**, if:
- Minimal features
- Simple functionality like IoT device that sends data to the NMS
- Some simple features enabled for basic networking functionalities like firewall, DHCP
- **Rationale:** the affected user base should be accounted for in the risk definition
- **[SRU-L-0]** single household or a small business, small ammount of SRUs
- **[SRU-L-1]** medium or large sized company with possibly multiple operation sites, medium ammount of SRUs
- **[SRU-L-2]** public telecommunication network providers, Internet service providers, large amount of SRUs
For **likelihood** select **high**, if:
- Exposed connectivity services like VPN and SDN
- Number of provided network servcies is high
- Multiple interconnected sites
- Complexity of managed network element implementation
For **impact** select **low**, if:
- Limited device capabilities
- Idempotent design
- **[COM-L-0]** Minimal features to collect and send data to the NMS like IoT devices
- **[COM-L-1]** Some simple features to enable basic networking like firewall, DHCP
- **[COM-L-2]** Dynamic routing table modifications or exposed connectivity services like VPN and SDN
- **[COM-L-3]** Complex network element with sophisticated functions and supporting services
For **impact** select **high**, if:
- Managed element does dynamic routing table modifications
- Complex network element with sophisticated functions and supporting services
- Multiple interconnected sites
- Security expectations of intentednetwork segment operation
- **Rationale:** NIS2 identifies entities that require higher level of protection. The important and essential classificatoins are combined as the NIS2 does't make additional cybersecurity requirements based on classification.
- **[EXP-L-0]** Undefined
- **[EXP-L-1]** NIS2 important or essential entity
#### 4.5.1.3 Security expectations of the deployment context
- Access to network used for communication between elements
-**[ACC-L-0]** Network physically isolated from public networks with strong physical access control procedures
-**[ACC-L-1]** Like L-0, but network has a single physical connection to public networks and strong internal segmentation and access controls that limit spread of compromise
-**[ACC-L-2]** Private network with multiple connections to public networks filtered by firewalls, no internal segmentation
-**[ACC-L-3]** Everything else
Expectation is hard to describe as a sum of likelihood and impact. Therefore this risk factor is evaluated directly as perceived by the market the product is made available.
**Key:** [NIS2]
**Rationale:** NIS2 identifies entities that require higher level of protection. The important and essential classifications are combined as the NIS2 does't make additional cybersecurity requirements based on classification. The additional mechanisms are often national level.
- The deployment context has other mechanisms that helps to identify and react to the security compromises
For risk level, select **low** if:
- NIS2 status is undefined
- The intended deployment target is a household or a small business
For risk level, select **medium** if:
- NIS2 status is undefined
- The product serves a larger audience
- The managed element is widely used and
For risk level, select **high** if:
- The product is targeted to NIS2 important or essential entities
The table below is an example, how the example use cases could be mapped to different risk factors.
If the actual use case cannot be clearly assigned, the manufacturer shall include all the dimensions of SRU, COM, EXP and ACC in his considerations and document the applicable factors.
**Table 4.5.2-1: Mapping of use cases**
**Table 4.5.2-1: Example mapping of use cases**
| Use case | [SRU] | [Complexity] | [NIS2] | [Segment] |
The To Be Defined (TBD) represent manufacturer design choices and what market the product is intented to be used in.
The product can be targeted to an audience, where the given risk factor evaluation is different.
For example the [4.4.2.1 Office network] evaluation table could be expanded to all existing combinations of low, medium, and high, in the risk factors that has TBD in place.
When the same product is provided to multiple different markets, highest risk factor shall be used.
[4.4.1.1 IoT network with monitoring data collection]:#4411-iot-network-with-monitoring-data-collection
[4.4.1.2 Home network deployment]:#4412-home-network-deployment
@@ -594,9 +679,9 @@ The chosen method shall follow the intent in the CRA by protecting the data tran