Commit 58e1cf8d authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Clause 5 rationals update

parent ea39c607
Loading
Loading
Loading
Loading
+9 −5
Original line number Diff line number Diff line
@@ -983,14 +983,18 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P

- REFERENCE: 	REQ-PKI-DM-01
  - REQUIREMENT: The product shall only maintain configuration data sufficient to connect to other elements of the PKI system that the product serves.
  - RATIONALE: Unecessary elements adds unecessary complexity and potential attack surface.
  - RATIONALE: Unnecessary network configuration elements add complexity and increase the potential attack surface. 
  - APPLICABILITY: UC1, UC2, UC3, and UC5

  - REFERENCE: 	REQ-PKI-DM-01
  - REQUIREMENT: The product shall only maintain configuration data sufficient to provide PKC management functions.
  - RATIONALE: Unnecessary PKC management function configurations (as defined per use case in Annex U) introduce unnecessary complexity and avoidable risks.
  - APPLICABILITY: UC1, UC2, UC3, and UC5

- REFERENCE: 	REQ-PKI-DM-02
  - REQUIREMENT: The product shall only maintain and process user data necessary for certificate management (e.g. certificate requests, updates)
  - RATIONALE: XXX
  - NOTE:XXX
  - APPLICABILITY: XXXX
  - REQUIREMENT: The product shall only maintain and process user data necessary for certificate management (e.g. certificate requests, updates).
  - RATIONALE: For each use case, only user data necessary for the certificate management functions identified in Annex U are required.
  - APPLICABILITY: All use cases.

### 5.8.2 Secret management
- REFERENCE: REQ-PKI-DM-03