Commit 72586e51 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Update file EN-304-624.md

parent 9b897938
Loading
Loading
Loading
Loading
+59 −101
Original line number Diff line number Diff line
@@ -2007,7 +2007,27 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
    - Logging architecture.
    - Configuration files.
    - Audit records.
    - Tests records

- REFERENCE: ACC-PKI-INT-05
  - OBJECTIVE:
    - Verify that the frequency of audit log signing events is configurable.
  - PREPARATION:
    - Administration documentation.
    - Configuration access.
  - ACTIVITIES:
    - Review available configuration settings.
    - Modify integrity protection frequency parameters.
    - Verify that changes are applied.
    - Verify operation using multiple configured frequencies.
  - VERDICT:
    - SUCCESS: Signing frequency is configurable and functions correctly.
    - FAIL: Signing frequency cannot be configured or configuration changes are ineffective.
  - EVIDENCE:
    - Configuration files.
    - Administrative procedures.
    - System logs.
    - Test records.

## 6.8 Data minimisation
### 6.8.1 General
@@ -2015,19 +2035,16 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
- REFERENCE: ACC-PKI-DM-01
  - OBJECTIVE:
    Determine whether the product only maintains network configuration data necessary for communication with PKI system elements required by the applicable use case and does not maintain unnecessary network configuration information.

  - PREPARATION:
    - Product architecture and deployment documentation.
    - List of external components and interfaces to connect to.
    - Access to configuration files, administrative guides, and installation procedures.
  
  - ACTIVITIES:
    1. Review the product design and configuration documentation.
    2. Identify all stored network configuration parameters.
    3. Verify that each configured endpoint, interface, protocol, and network parameter is required to support the applicable PKI use case.
    4. Verify that no unused, unnecessary, or undocumented network configuration data are maintained.
    5. Confirm that administrators cannot configure network connections unrelated to the PKI functions provided by the product.

  - VERDICT:
    - SUCCESS:
      - All maintained network configuration data are necessary for communication with PKI elements required by the applicable use case.
@@ -2035,7 +2052,6 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
    - FAIL:
      - The product maintains network configuration data unrelated to the applicable PKI functions.
      - Unnecessary interfaces or endpoints are configured or can be configured without operational justification.

  - EVIDENCE:
    - Product architecture documentation.
    - Configuration files and parameter listings.
@@ -2044,25 +2060,20 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
- REFERENCE: REQ-PKI-DM-02
  - OBJECTIVE:
    Verify that the product only maintains and processes user data necessary for certificate management.

  - PREPARATION:
    - Access to the product's user data storage and certificate management logs.

  - ACTIVITIES:
    - Review the user data stored and processed by the product.
    - Identify all user data related to certificate management (e.g., certificate requests, updates).
    - Verify that no unnecessary or unrelated user data is stored or processed.
    - Confirm that the stored and processed data is limited to what is required for certificate management.

  - VERDICT:
    - SUCCESS: If the product only maintains and processes user data necessary for certificate management.
    - FAIL: If unnecessary or unrelated user data is found.

  - EVIDENCE:
    - List of stored and processed user data.
    - Documentation or logs showing the alignment of user data with certificate management requirements.


- REFERENCE: ACC-PKI-DM-03
  - OBJECTIVE:
    Determine whether the product maintains only the configuration data required to implement the PKC management functions applicable to the use case.
@@ -2093,62 +2104,42 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
    - Assessment records mapping configuration parameters to PKC functions.

- REFERENCE: ACC-PKI-SBDC-03

  - OBJECTIVE:

    - Determine whether the product only stores and processes user data required to perform certificate management functions.

  - PREPARATION:

  - Obtain data flow diagrams.
  - Obtain database schemas and storage specifications.
  - Obtain descriptions of certificate management operations.
    - Data flow diagrams.
    - Database schemas and storage specifications.
    - Descriptions of certificate management operations.
    - Identify user data processed by the product.

  - ACTIVITIES:

  1. Review the certificate management workflows.
  2. Identify all categories of user data collected, stored, processed, and transmitted.
  3. Verify that each category of user data is necessary to support certificate management functions.
  4. Verify that unnecessary user information is neither stored nor processed.
  5. Review logs and temporary storage mechanisms to ensure unnecessary user data are not retained.

    - Review the certificate management workflows.
    - Identify all categories of user data collected, stored, processed, and transmitted.
    - Verify that each category of user data is necessary to support certificate management functions.
    - Verify that unnecessary user information is neither stored nor processed.
    - Review logs and temporary storage mechanisms to ensure unnecessary user data are not retained.
  - VERDICT:

    - SUCCESS:

      - All maintained and processed user data are necessary to perform certificate management functions.
      - No unnecessary user data are collected, processed, or retained.
    - FAIL:

      - User data unrelated to certificate management are collected, processed, or retained.
      - Excessive or unnecessary data are stored by the product.

  - EVIDENCE:

    - Data flow diagrams.
  - Database schemas.
    - Database schemas (if any).
    - Data dictionaries.
    - Configuration and logging documentation.
    - Assessment records demonstrating data mapping.


- REFERENCE: ACC-PKI-SBDC-04


  - OBJECTIVE:

    - Determine whether all key generation operations are performed exclusively by approved Secure Cryptographic Devices (SCDs) or remote Key Management Systems (KMSs) implementing cryptographic mechanisms conformant with Annex K.

  - PREPARATION:

  - Obtain the cryptographic architecture documentation.
  - Obtain documentation for the SCD or KMS.
  - Obtain cryptographic algorithm specifications and configuration information.
    - Cryptographic architecture documentation.
    - Documentation for the SCD or KMS.
    - Cryptographic algorithm specifications and configuration information.
    - Identify all key generation functions.

  - ACTIVITIES:

  1. Review the product's cryptographic architecture.
  2. Identify all key generation operations.
  3. Verify that keys are generated only by approved SCDs or remote KMSs.
@@ -2217,108 +2208,75 @@ The validity of the cryptographic mechanisms used to encure those funtions is co
  - Test results and interface traces.
  - Assessment records.


### 6.8.2 Secret management

- REFERENCE: ACC_PKI_DM_03

  - OBJECTIVE: Verify the product only creates keys by means of a SCD appropriate for this use.

  - PREPARATION: Document the profiles of private and symmetric keys manipulated by the product, and how they are created by the product.

  - ACTIVITIES: Verify that all keys are created by an appropriate secure cryptographic device.

  - OBJECTIVE:
    - Verify the product only creates keys by means of a SCD appropriate for this use.
  - PREPARATION:
    - Document the profiles of private and symmetric keys manipulated by the product, and how they are created by the product.
  - ACTIVITIES: 
    - Verify that all keys are created by an appropriate secure cryptographic device.
  - VERDICT:
    - SUCCESS: Verification passes
    - FAIL: Identification of keys not created by SCD or with improper algorithm or size.

  - EVIDENCE:

    - The documentation of private and symmetric keys profiles and how these keys are created.

REFERENCE: ACC_PKI_DM_04
- OBJECTIVE:
  - Verify that the product establishes and maintains a secure and correctly configured communication link with the SCD, and that the SCD interface is properly configured and called.

- PREPARATION:
  - Document the following:
    - The communication protocols (e.g., TLS, IPsec) and their configurations used to connect to the SCD.
    - The SCD interface specifications, including supported commands, data formats, and authentication mechanisms.
    - The expected behavior of the product when interacting with the SCD (e.g., error handling, retries, timeouts).

- ACTIVITIES:
  - Verify that the communication link with the SCD is encrypted and authenticated according to the documented protocols and configurations.
  - Verify that the product correctly configures the SCD interface (e.g., parameters, credentials, or certificates).
  - Verify that all calls to the SCD interface use the correct commands, data formats, and authentication mechanisms as specified.
  - Test edge cases, such as network interruptions or invalid responses, to ensure robust handling.

- VERDICT:
  - SUCCESS: All communication links are secure, and the SCD interface is correctly configured and called.
  - FAIL: Identification of insecure communication links, misconfigured SCD interfaces, or incorrect calls to the SCD interface.

- EVIDENCE:
  - Documentation of the communication protocols, configurations, and SCD interface specifications.
  - Logs or test results demonstrating secure communication and correct SCD interface calls.
  - Evidence of error handling and robustness during edge case testing.


- REFERENCE: ACC_PKI_DM_05

  - OBJECTIVE: Verify the product does not persistently store private or symmetric keys in plaintext form.

  - OBJECTIVE: 
    - Verify the product does not persistently store private or symmetric keys in plaintext form.
  - PREPARATION: Document the profiles of private and symmetric keys manipulated by the product, and how they are manipulated by the product.

  - ACTIVITIES: Verify that keys accessed in plaintext form are only used to perform a single operation once, or operations in a single batch.

  - VERDICT: SUCCESS if the verification passes; else FAIL.

  - EVIDENCE:

    a) The documentation of private and symmetric keys profiles and how these keys are manipulated.

- REFERENCE: ACC_PKI_DM_06

  - OBJECTIVE: Verify public keys stored within the product outside a secure cryptographic device are protected against undetected modification, and that public keys are not released or used after a detected modification.

  - PREPARATION: Document public keys manipulated by the product outside a secure cryptographic device, and how they are manipulated by the product.

  - OBJECTIVE:
    - Verify public keys stored within the product outside a secure cryptographic device are protected against undetected modification, and that public keys are not released or used after a detected modification.
  - PREPARATION:
    - Document public keys manipulated by the product outside a secure cryptographic device, and how they are manipulated by the product.
    - Ability to directly modify such a stored public key. Ability to directly modify digital signatures, keyed hashes, or authentication codes associated to such stored public keys.

    - Ability to request the public key (if applicable). Ability to trigger an action of the product making it use the public key (if applicable).

  - ACTIVITIES: For every public key stored within the product outside a secure cryptographic device:

    a) directly modify the stored public key;

    b) attempt to request the public key;

    c) verify the request fails;

    d) attempt to trigger an operation whereby the product makes use of the public key;

    e) verify the operation fails because of the state of the public key;

    f) restore the stored public key;

    g) directly modify the digital signature, keyed hash, or authentication code associated to the stored public key;

    h) attempt to request the public key;

    i) verify the request fails;

    j) attempt to trigger an operation whereby the product makes use of the public key;

    k) verify the operation fails because of the state of the public key.

  - VERDICT: SUCCESS if all the verifications pass; else FAIL.

  - EVIDENCE:

    a) The documentation of public keys and how they are manipulated;

    b) the way the public keys were requested, and the response from the product;

    c) the way operations making use of public keys were attempted to be triggered, and the response from the product;
    - The documentation of public keys and how they are manipulated;
    - The way the public keys were requested, and the response from the product;
    - The way operations making use of public keys were attempted to be triggered, and the response from the product;

- REFERENCE: ACC_PKI_DM_07