Commit 0954ebc0 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Annex B.2.1: Reduce and rewrite risk factors

Now that we understand how much of the cybersecurity of a network
interface is outsourced to the host system, dramatically reduce the
number of risk factors. Add risk factor for environment of initial use
and setup to handle integrator use cases.
parent d8ea1d2a
Loading
Loading
Loading
Loading
+32 −110
Original line number Diff line number Diff line
@@ -2531,85 +2531,43 @@ Optional:

### B.2.1 List of risk factors

Risk factors determine which mitigation(s) satisfy each of the technical cybersecurity requirements in clause 5.2. The manufacturer of a product determines the level of each risk factor via its own independent risk assessment.
The risk factor levels determine the impact and likelihood of each threat in this security analysis. Risk factor levels also specify which requirements reduce the risk of each threat to satisfy all of the technical cybersecurity requirements in clause 5.2.

Risk factors may increase the likelihood of an incident, increase the impact of an incident, or both. As a result, different mitigation strategies may be more or less relevant to different risk factors.

The overall risk related to each use case should be considered as a result of combining risk factors affecting both likelihood and impact of an incident.

**[PHY]** Degree of physical access to the device
### B.2.2 \[RF-PHY\] Physical access to product

Description: Exposure of the device to physical access by users.
Description: Exposure of the product to physical access by unauthorized agents.

Rationale: More users with physical access to the device increases the likelihood of an attack via physical interfaces.
Rationale: More unauthorized agents with physical access to the product increases the likelihood of an attack via the product's physical interfaces.

Type: Affects likelihood of attacks originating from physical access
  * **\[RF-PHY-L-0\]** Foreseeable use is physical access only to authorized users or not a physical network interface
  * **\[RF-PHY-L-1\]** Foreseeable use is incidental physical access by unauthorized users
  * **\[RF-PHY-L-2\]** Foreseeable use is prolonged physical access by unauthorized users

  * **[PHY-L-0]** Foreseeable use is physical access only by authorized users
  * **[PHY-L-1]** Foreseeable use is incidental physical access by untrusted users
  * **[PHY-L-2]** Foreseeable use is frequent physical access by untrusted users

**[SFT]** Degree of local software access to the host system

Description: How many agents have unprivileged software access to the host system.

Rationale: More agents with software access on the host increase the likelihood of an attack originating from the host.

Type: Affects likelihood of attacks originating from the host system.

  * **[SFT-L-0]** Foreseeable use is effectively no agents on the host
  * **[SFT-L-1]** Foreseeable use is trusted agents
  * **[SFT-L-2]** Foreseeable use includes untrusted agents

**[NET]** Degree of public access to attached network
### B.2.3 \[RF-NET\] Access to attached network

Description: How publicly accessible the attached network is.

Rationale: The more unrestricted the access to the attached network is, the more likely a threat actor can send packets to the device.

Type: Affects likelihood of attacks originating from the network and impact of attacks on other systems.

  * **[NET-L-0]** Foreseeable use is in an isolated private network
  * **[NET-L-1]** Foreseeable use is in a private network with filtered connection to public network
  * **[NET-L-2]** Foreseeable use is in a public network
  * **\[RF-NET-L-0\]** Foreseeable use is in an isolated private network
  * **\[RF-NET-L-1\]** Foreseeable use is in a private network with filtered connection to public network
  * **\[RF-NET-L-2\]** Foreseeable use is in a public network

**[COM]** Complexity of product functions
### B.2.4 \[RF-COM\] Complexity of product functions

Description: How complex the available product functions are in its secure-by-default configuration.

Rationale: More complex functions means increased likelihood of errors in the implementation and more attack surface.

Type: Affects likelihood of all attacks.

  * **[COM-L-0]** Product implements minimal features necessary to send/recv packets but not the features in COM-L-1 or COM-L-2
  * **[COM-L-1]** Product implements features such as simple performance improvements which are more complex than COM-L-0 but less complex than those in COM-L-2
  * **[COM-L-2]** Product implements complex features such as encryption functions, RTOS managing radio, PXE boot, remote management, etc.

**[LIS]** Ease of reading from transmission media of directly attached network by unauthorized agents

Description: Likelihood that unauthorized agents can read data from the transmission media on the directly attached network. For example, a wireless network in an apartment that is accessible from the shared hallway or another apartment, or a wired network with exposed jacks in a public library.

Rationale: While confidentiality of data transmitted across public networks is usually handled by the system the network interface is integrated into, the network interface is usually responsible for confidentiality on the local directly attached network.

Type: Affects likelihood of attack.

  * **[LIS-L-0]** Foreseeable use is only authorized agents with access to directly attached network
  * **[LIS-L-1]** Foreseeable use includes occasional access by unauthorized agents to directly attached network
  * **[LIS-L-2]** Foreseeable use includes frequent access by unauthorized agents to directly attached network

**[ADM]** Availability and skill of administration

Description: What the availability and skill of administration is for the product.

Rationale: Skilled, fully resourced administration allows more risk transfer and can reduce the impact of incidents.

Type: Affects likelihood and impact of all attacks.
  * **\[RF-COM-L-0\]** Product implements minimal features necessary to send/recv packets but not the features in COM-L-1 or COM-L-2
  * **\[RF-COM-L-1\]** Product implements features such as simple performance improvements which are more complex than COM-L-0 but less complex than those in COM-L-2
  * **\[RF-COM-L-2\]** Product implements complex features such as encryption functions, RTOS managing radio, PXE boot, remote management, etc.

  * **[ADM-L-0]** Foreseeable use is with fully resourced professional administration
  * **[ADM-L-1]** Foreseeable use is with professional administration with limited resources
  * **[ADM-L-2]** Foreseeable use is with unskilled or no administration

**[SYS]** Impact of access to host system assets
### B.2.5 \[RF-HOS\] Impact of access to host system assets

Description: Measures the impact of the product's access to host system assets, which is a combination of the level of access and the sensitivity of the host system assets.

@@ -2617,59 +2575,29 @@ The communications bus used to connect to the host system usually controls the l

Rationale: An attacker can get access to host system functions via the product's access.

Type: Affects impact of all attacks.

  * **[SYS-L-0]** Little or no access to the host, or little or no sensitivity of host assets
  * **[SYS-L-1]** High degree of access to host and moderate sensitivity of host assets, or moderate access and high sensitivity
  * **[SYS-L-2]** High degree of access and high sensitivity of host assets

**[SDS]** Sensitivity of data stored

Description: Sensitivity of data stored on the product.

Rationale: The more sensitive the data stored, the higher the impact of compromise of that data.

Type: Affects impact of attack.

  * **[SDS-L-0]** Foreseeable use stores unimportant or no data
  * **[SDS-L-1]** Foreseeable use stores moderately sensitive data
  * **[SDS-L-2]** Foreseeable use stores highly sensitive data

**[SDT]** Sensitivity of data transmitted

Description: Sensitivity of data transmitted on the product.
  * **\[RF-HOS-L-0\]** Little or no access to the host, or little or no sensitivity of host assets
  * **\[RF-HOS-L-1\]** High degree of access to host and moderate sensitivity of host assets, or moderate access and high sensitivity
  * **\[RF-HOS-L-2\]** High degree of access and high sensitivity of host assets

Rationale: The more sensitive the data transmitted, the higher the impact of compromise of that data.

Type: Affects impact of attack.

  * **[SDT-L-0]** Foreseeable use transmits unimportant or no data
  * **[SDT-L-1]** Foreseeable use transmits moderately sensitive data
  * **[SDT-L-2]** Foreseeable use transmits highly sensitive data

**[FUN]** Sensitivity of functions
### B.2.6 \[RF-FUN\] Sensitivity of functions of product

Description: Sensitivity of functions of the product.

Rationale: The more sensitive the functions of the product, the higher the impact of denial-of-service or corruption of the functions.

Type: Affects impact of attack.
Rationale: The more sensitive the functions of the product, the higher the impact of unavailability or degradation of its functions.

  * **[FUN-L-0]** Foreseeable use is for unimportant functions
  * **[FUN-L-1]** Foreseeable use is for moderately sensitive functions, such as encrypting transmitted data
  * **[FUN-L-2]** Foreseeable use is for highly sensitive functions, such as primary management interface of host system
  * **\[RF-FUN-L-0\]** Foreseeable use is for unimportant functions
  * **\[RF-FUN-L-1\]** Foreseeable use is for moderately sensitive functions, such as encrypting transmitted data
  * **\[RF-FUN-L-2\]** Foreseeable use is for highly sensitive functions, such as primary management interface of host system

**[INT]** Integration in host system
### B.2.7 \[RF-INI\] Operational environment of initial setup

Description: How difficult it is to remove the product from the host system.
Description: The security of the operational environment in which the product is initially used and configured.

Rationale: The more integrated a product is in the host system, the harder it is to disable, remove, or replace it if it has an exploitable unpatched vulnerability or is no longer supported.
Rationale: A more secure operational environment for initial use and configurations affects the risk of the secure-by-default configuration.

Type: Affects impact of attack.

  * **[INT-L-0]** Product is connected to host system via external adapter
  * **[INT-L-1]** Product is connected to host system via internal adapter requiring disassembly to change
  * **[INT-L-2]** Product is fully integrated into and cannot be removed from host system
  * **\[RF-INI-L-0\]** Product is initially used and configured in an extremely secure operational environment, such as a professional engineer in an integrator's factory
  * **\[RF-INI-L-1\]** Product is initially used and configured in a moderately secure operational environment, such as a computer professional at home
  * **\[RF-INI-L-2\]** Product is initially used and configured in an insecure operational environment, such as an unskilled user installing it in a laptop while in a cafe

## B.3 Assumptions

@@ -2715,15 +2643,9 @@ For each threat, both likelihood and impact must be Low before the risk is consi

The risk factors by type are:

  * Likelihood: PHY SFT NET COM ADM LIS

  * Impact: SYS SDS SDT FUN INT

The mitigations that reduce risk by type are:

  * Likelihood: KEVD, KEVA, KEVM, KEVT, SCAN, SCFS, SSCA, FZ95, BTIN, IMSL, MSAF-\*, MZRO-\*, ADEF, DPAH, PDDI-\*, SUDC, SUVP, SUOE, SUAP, SUAO, CDTX, JSTY, RSET, INST, DELE, VULH
  * Likelihood: PHY NET COM INI

  * Impact: IMSL, DCTX, DJST, IDST, NTFY, WDOG, LOGG, SDRF, SDTR
  * Impact: NET HOS FUN

### B.4.3 List of threats, risk assessments, and mitigations