@@ -503,9 +503,11 @@ A physical network interface is attached to a host system bus which may be acces
The attached network may be an isolated private network, a private network with a filtered connection to a public network, or a public network directly accessible by many untrusted agents.
## 4.5 Distribution of security functions
## 4.4 Distribution of Security Functions
### 4.5.1 General
<mark>Editor's Note: The clause should explain how the security functions are distributed among the product and its environment, referencing as appropriate elements of the operational environment defined in prior clauses. This analysis is not limited to which security functions products expect to get but should also explain which functions they themselves provide.</mark>
### 4.4.1 General
For each cybersecurity requirement, a product may:
@@ -515,7 +517,7 @@ For each cybersecurity requirement, a product may:
For example, most individual hardware components do not have a built-in method of securely updating any firmware in the product. Usually this requires a full-featured system running an operating system which can check for firmware updates, download and verify them, and carry out the process of updating the firmware.
### 4.5.2 Security functions provided outside the product
### 4.4.2 Security functions provided outside the product
The following security functionalities are frequently handled by the operating system or other external component:
@@ -527,7 +529,7 @@ The following security functionalities are frequently handled by the operating s
* Deletion and transfer of user data
* Provision of cryptographic keys to network interface
### 4.5.3 Security functions provided to other components
### 4.4.3 Security functions provided to other components
The network interface provides the following security functions to other parts of the system: