@@ -698,7 +698,6 @@ The product contains a number of assets that need privileged access to use. The
-**U.ProductAdministrator**: Install, configure, and maintain the product, ensuring its proper operation and security.
-**U.ProductOperator**: Performs operational tasks to ensure the availability and integrity of the product and data, e.g. execute system backups and recovery procedures to prevent data loss, monitor product health and performance, manage routine operational tasks, such as certificate issuance workflows.
-**U.Officer (or Registration Authority Officer)**: Manage certificate life-cycle operations, including approvals and revocations e.g. Configure profiles, policies, and security parameters, review and approve or reject certificate requests based on policy compliance, initiate and manage certificate revocation (e.g., due to compromise, expiration, or policy violations), verify the identity and authenticity of certificate applicants, ensure that certificate issuance and revocation processes align with organizational policies.
-**U.Auditor**: Authorized to monitor and review product operations logs to ensure compliance and security.
-**U.End_User**: Individuals or systems that request certificates or check certificate status for authentication, encryption, or digital signing purposes.
@@ -1404,7 +1403,7 @@ The assessment criteria for each security requirements are described in a struct
- ACTIVITIES:
- Review the product documentation, component inventory, bill of materials, or equivalent information to identify the elements contained in the product (which may include software, firmware, or hardware elements, as applicable) and their relevant versions or patch levels, where available.
- Perform vulnerability scanning, where technically feasible, on the product or relevant components to identify candidate vulnerabilities affecting elements contained in the product.
- Assess, in accordance with prEN 40000-1-3 [X], the vulnerabilities identified through correlation of scanning results, product identification information, vendor advisories, and recognized public vulnerability sources.
- Assess, in accordance with prEN 40000-1-3 [\[i.17\]](#_ref_i.17), the vulnerabilities identified through correlation of scanning results, product identification information, vendor advisories, and recognized public vulnerability sources.
- For each identified known exploitable vulnerability, review the vulnerability assessment and verify whether it demonstrates that the vulnerability is not exploitable in the product:
- Where the treatment of an identified known exploitable vulnerability relies on user guidance, review the user guidance and verify that it specifically addresses the conditions to prevent exploitation.
- Verify that no identified known exploitable vulnerability affecting the product remains without:
@@ -1416,7 +1415,7 @@ The assessment criteria for each security requirements are described in a struct
- EVIDENCE:
- Vulnerability scanning results, including the tools and vulnerability databases used.
- Recognized public vulnerability sources, vendor advisories, and product identification information used in the assessment.
- Vulnerability assessment records and conclusions produced in accordance with prEN 40000-1-3 [X].
- Vulnerability assessment records and conclusions produced in accordance with prEN 40000-1-3 [\[i.17\]](#_ref_i.17).
- REQ-PKI-AAC-01Product user guidance relied upon to prevent exploitation, where applicable.