Commit f93cddcc authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Refactored 4.5 Users

parent 6db97431
Loading
Loading
Loading
Loading
+20 −11
Original line number Diff line number Diff line
@@ -659,17 +659,26 @@ NSM can provide the following services to 3rd. party applications and for the co

## 4.5 Users

<mark>Editor's Note: Some common definition of user categories are proposed in clause 3.1 above for consistency across vertical standards. Users can include both integrators and end users (individual or group / consumer or organisation), as well as users with privileged rights or professional training such as administrators. Users can be professional users or consumers and may have different levels of cybersecurity knowledge. Both professional and less experienced users may also have disabilities and may be using assistive technology to access the product. In addition, where a product is used in a public space there may be indirect users who are impacted by the device and whose cybersecurity needs should be considered.</mark>

<mark>Editor’s Note: Definitions of users must not consider profession but shall rather be based on a characterisation of needs in a certain market segment (e.g., avoid “journalist” in favour of “privacy-conscious user”), covering also health, safety and accessibility of the product.</mark>

<mark>Editor’s Note: Should cover use by vulnerable groups where applicable, like children or elderly.</mark>

Human users of the system are natural persons, trained and qualified at NMS administrators, and authorised to manage the NMS and the connected managed elements. Administrators typically access the system through a HTTPS GUI, console, or by VPN connection.

Machine users are servers or any other type of a computer that are identified and authenticated by communication protocols that protect the communication between the NMS and the machine user. Once the protected communication has been established, the machine user receives the according authorisation by the NMS.

Service Requesting Users do neither have a direct interface to, nor could they interact or login via other ways to the NMS. Nevertheless, SRUs rely on the correct functioning of the managed elements and therewith on the NMS.
**Product users** are consumer customers or entities, like companies and institutions, whom use the product in its intenteded and foreseeable use.
The definition targeting can vary from a single person to nations.

**System users** are natural persons.
Administrators typically access the system through a HTTPS GUI, console, or by VPN connection.
System users can include both integrators and end users (individual or group / consumer or organisation), as well as users with privileged rights or professional training such as administrators.
System users can be professional users or consumers and may have different levels of cybersecurity knowledge.
Both professional and less experienced users may also have disabilities and may be using assistive technology to access the product.

**Machine users** are servers or any other type of a computer that are identified and authenticated by communication protocols that protect the communication between the product and the machine user.
Once the protected communication has been established, the machine user receives the according authorisation by the product.

**Service Requesting Users** do neither have a direct interface to, nor could they interact or login via other ways to the product.
SRUs are the beneficiaries of the product operation and do not participate in the configuration and control of the product.
Typically the product does not classify the traffic source.
The source can be a machine used by a human user, an application workload using the network.
This group includes also childern and elderly.

**Subject** is later used in the identity and access management requirements when both, product users and machine users are adressed as a group.
It should not be mixed with product users, as the subject is always more clearly defined in the context, nor with service requesting users.

## 4.6 Use Cases