Commit 44bb48bf authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Use new threat assessment for sniffing data transmitted

parent 17b08b02
Loading
Loading
Loading
Loading
+46 −32
Original line number Diff line number Diff line
@@ -1415,27 +1415,27 @@ This clause lists all the mitigations necessary to meet requirements for each se

### 5.3.1 Wired network interface risk mitigation sets

SP-WD-1: SCFS, SUDC, (SUVP or SUOE), (NTFY or WDOG), LOGG
SP-WD-1: SCFS, SUDC, (SUVP or SUOE), DJST, (NTFY or WDOG), LOGG

SP-WD-2: (KEVD or KEVA or KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, PDDI-4, SUDC, (SUVP or SUOE), CDST, CDTX, DCTX, DJST, WDOG, JSTY, LOGG, VULH
SP-WD-2: (KEVD or KEVA or KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, PDDI-4, SUDC, (SUVP or SUOE), CDST, DCTX, DJST, WDOG, JSTY, LOGG, VULH

SP-WD-3: (KEVD or KEVA or KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, PDDI-4, SUDC, (SUVP or SUOE), CDST, CDTX, DCTX, (NTFY or WDOG), JSTY, LOGG, VULH
SP-WD-3: (KEVD or KEVA or KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, PDDI-4, SUDC, (SUVP or SUOE), CDST, DCTX, DJST, (NTFY or WDOG), JSTY, LOGG, VULH

SP-WD-4: (KEVD or KEVA or KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-\*, SUDC, (SUVP or SUOE), CDST, CDTX, DCTX, DJST, NTFY, WDOG, JSTY, LOGG, VULH
SP-WD-4: (KEVD or KEVA or KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-\*, SUDC, (SUVP or SUOE), CDST, DCTX, DJST, NTFY, WDOG, JSTY, LOGG, VULH

### 5.3.2 Wireless network interface risk mitigation sets

SP-WL-1: (KEVD or KEVA or KEVT or SCAN), SCFS, SSCA, IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, SUDC, (SUVP or SUOE), CDST, CDTX, IDST, DCTX, (NTFY or WDOG), JSTY, LOGG, (RSET or INST or DELE), SDRF, VULH
SP-WL-1: (KEVD or KEVA or KEVT or SCAN), SCFS, SSCA, IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, SUDC, (SUVP or SUOE), CDST, CDTX, IDST, DCTX, DJST, (NTFY or WDOG), JSTY, LOGG, (RSET or INST or DELE), SDRF, VULH

SP-WL-2: KEVD, KEVA, (KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, PDDI-4, SUDC, (SUVP or SUOE), CDST, CDTX, IDST, DCTX, (NTFY or WDOG), JSTY, LOGG, (RSET or INST or DELE), SDRF, VULH
SP-WL-2: KEVD, KEVA, (KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, PDDI-4, SUDC, (SUVP or SUOE), CDST, CDTX, IDST, DCTX, DJST, (NTFY or WDOG), JSTY, LOGG, (RSET or INST or DELE), SDRF, VULH

SP-WL-3: KEVD, KEVA, (KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-\*, SUDC, (SUVP or SUOE), CDST, CDTX, IDST, DCTX, (NTFY or WDOG), JSTY, LOGG, (RSET or INST or DELE), SDRF, VULH
SP-WL-3: KEVD, KEVA, (KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-\*, SUDC, (SUVP or SUOE), CDST, CDTX, IDST, DCTX, DJST, (NTFY or WDOG), JSTY, LOGG, (RSET or INST or DELE), SDRF, VULH

### 5.3.3 Virtual network interface risk mitigation sets

SP-VI-1: (KEVD or KEVA or KEVT or SCAN), SCFS, IMSL or (MSAF-\*, MZRO-\*), SUDC, (SUVP or SUOE), CDST, IDST, DCTX, (NTFY or WDOG), JSTY, LOGG, SDRF, VULH
SP-VI-1: (KEVD or KEVA or KEVT or SCAN), SCFS, IMSL or (MSAF-\*, MZRO-\*), SUDC, (SUVP or SUOE), CDST, IDST, DCTX, DJST, (NTFY or WDOG), JSTY, LOGG, SDRF, VULH

SP-VI-2: KEVD, KEVA, (KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, PDDI-3, PDDI-4, SUDC, (SUVP or SUOE), CDST, CDTX, IDST, DCST, DCTX, DJST, NTFY, WDOG, JSTY, LOGG, (RSET or INST or DELE), SDRF, SDTR, VULH
SP-VI-2: KEVD, KEVA, (KEVT or SCAN), SCFS, SSCA, (FZ95 or BTIN or IMSL), IMSL or (MSAF-\*, MZRO-\*), ADEF, DPAH, PDDI-1, PDDI-3, PDDI-4, SUDC, (SUVP or SUOE), CDST, IDST, DCST, DCTX, DJST, NTFY, WDOG, JSTY, LOGG, (RSET or INST or DELE), SDRF, SDTR, VULH

# 6 Conformity Assessment

@@ -1880,21 +1880,35 @@ Mitigations for Impact:

* High to Low: CDST, DJST, LOGG

**[TH-UADT]:** Attacker may use network access to get unauthorized access to confidential data transmitted by the product.
#### C.4.3.5 TH-UADT: Unauthorized access to confidential data transmitted

| Risk factors | Likelihood |
|--------------|------------|
| LIS = 2      | High       |
| LIS = 1      | Medium     |
| LIS = 0      | Low        |
Attacker may use network access to get unauthorized access to confidential data transmitted by the product.

| Risk factors | Impact |
|--------------|--------|
| SDT = 2      | High   |
| SDT = 1      | Medium |
| SDT = 0      | Low    |
| Risk factors | Likelihood | Security profiles |
|--------------|------------|-------------------|
| LIS = 0      | Low        | WD-\*, VI-1, VI-2 |
| LIS = 1      | Medium     | WL-1              |
| LIS = 2      | High       | WL-2, WL-3        |

| Risk factors | Impact | Security profiles  |
|--------------|--------|--------------------|
| SDT = 0      | Low    | none               |
| SDT = 1      | Medium | WD-\*, WL-\*, VI-1 |
| SDT = 2      | High   | VI-2               |

Requirements that mitigate this threat: CDTX, DMIN

Mitigations for Likelihood:

* Medium to Low: CDTX

* High to Low: CDTX

Mitigations for Impact:

* Medium to Low: DJST

Requirements: CDTX, DMIN, LMAS
* High to Low: DJST

**[TH-AVAI]:** Attacker may exploit vulnerabilities in the product to reduce availability of product assets.

@@ -1984,14 +1998,14 @@ Requirements: NKEV, SCUD, SSDD, LMII, LMAS, LOGG
|----------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|---------|
| UC-WD-1  | 0   | 0   | 0   | 1   | 2   | 0   | 0   | 0   | 0   | 1   | 2   | SP-WD-1 |
| UC-WD-2  | 0   | 0   | 0   | 1   | 0   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-1 |
| UC-WD-3  | 0   | 0   | 1   | 1   | 0   | 1   | 1   | 0   | 1   | 2   | 1   | SP-WD-2 |
| UC-WD-4  | 0   | 0   | 2   | 1   | 0   | 2   | 2   | 0   | 1   | 2   | 1   | SP-WD-2 |
| UC-WD-5  | 0   | 0   | 2   | 1   | 1   | 2   | 1   | 0   | 1   | 1   | 1   | SP-WD-2 |
| UC-WD-6  | 1   | 1   | 1   | 1   | 0   | 1   | 1   | 0   | 1   | 1   | 1   | SP-WD-3 |
| UC-WD-3  | 0   | 0   | 1   | 1   | 0   | 0   | 1   | 0   | 1   | 2   | 1   | SP-WD-2 |
| UC-WD-4  | 0   | 0   | 2   | 1   | 0   | 0   | 2   | 0   | 1   | 2   | 1   | SP-WD-2 |
| UC-WD-5  | 0   | 0   | 2   | 1   | 1   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-2 |
| UC-WD-6  | 1   | 1   | 1   | 1   | 0   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-3 |
| UC-WD-7  | 1   | 1   | 1   | 1   | 2   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-3 |
| UC-WD-8  | 1   | 1   | 2   | 1   | 2   | 2   | 1   | 0   | 1   | 1   | 1   | SP-WD-3 |
| UC-WD-9  | 0   | 2   | 1   | 1   | 0   | 2   | 2   | 0   | 1   | 2   | 1   | SP-WD-4 |
| UC-WD-10 | 2   | 2   | 1   | 1   | 1   | 2   | 2   | 0   | 0   | 0   | 1   | SP-WD-4 |
| UC-WD-8  | 1   | 1   | 2   | 1   | 2   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-3 |
| UC-WD-9  | 0   | 2   | 1   | 1   | 0   | 0   | 2   | 0   | 1   | 2   | 1   | SP-WD-4 |
| UC-WD-10 | 2   | 2   | 1   | 1   | 1   | 0   | 2   | 0   | 0   | 0   | 1   | SP-WD-4 |

#### C.5.2.2 Wireless network interface use cases

@@ -1999,7 +2013,7 @@ Requirements: NKEV, SCUD, SSDD, LMII, LMAS, LOGG
|----------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|---------|
| UC-WL-1  | 0   | 0   | 0   | 2   | 0   | 0   | 1   | 1   | 1   | 1   | 1   | SP-WL-1 |
| UC-WL-2  | 0   | 0   | 1   | 2   | 2   | 1   | 0   | 0   | 0   | 1   | 2   | SP-WL-1 |
| UC-WL-3  | 0   | 0   | 2   | 2   | 0   | 2   | 2   | 1   | 1   | 1   | 1   | SP-WL-2 |
| UC-WL-3  | 0   | 0   | 2   | 2   | 0   | 1   | 2   | 1   | 1   | 1   | 1   | SP-WL-2 |
| UC-WL-4  | 1   | 1   | 2   | 2   | 0   | 2   | 2   | 1   | 1   | 1   | 1   | SP-WL-2 |
| UC-WL-5  | 0   | 1   | 1   | 2   | 2   | 1   | 1   | 1   | 1   | 1   | 1   | SP-WL-2 |
| UC-WL-6  | 1   | 1   | 2   | 2   | 2   | 2   | 2   | 1   | 1   | 1   | 1   | SP-WL-3 |
@@ -2029,9 +2043,9 @@ Security profiles are associated with sets of risk factor levels.
| Security profile | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT |
|------------------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|
| SP-WD-1          | 0   | 0   | 0   | 1   | 2   | 0   | 1   | 0   | 1   | 1   | 2   |
| SP-WD-2          | 0   | 0   | 2   | 1   | 1   | 2   | 2   | 0   | 1   | 2   | 1   |
| SP-WD-3          | 1   | 1   | 2   | 1   | 2   | 2   | 1   | 0   | 1   | 1   | 1   |
| SP-WD-4          | 2   | 2   | 2   | 1   | 1   | 2   | 2   | 0   | 1   | 2   | 1   |
| SP-WD-2          | 0   | 0   | 2   | 1   | 1   | 0   | 2   | 0   | 1   | 2   | 1   |
| SP-WD-3          | 1   | 1   | 2   | 1   | 2   | 0   | 1   | 0   | 1   | 1   | 1   |
| SP-WD-4          | 2   | 2   | 2   | 1   | 1   | 0   | 2   | 0   | 1   | 2   | 1   |

#### C.6.2.2 Wireless network interface security profiles