@@ -2206,13 +2206,23 @@ Once the present document is cited in the Official Journal of the European Union
Presumption of conformity stays valid only as long as a reference to the present document is maintained in the list published in the Official Journal of the European Union. Users of the present document should consult frequently the latest list published in the Official Journal of the European Union.
Other Union legislation may be applicable to the product(s) falling within the scope of the present document.
# Annex C (informative): Risk identification and assessment methodology
# Annex B (informative): Security analysis
## C.1 Assets
This Annex applies state of the art methodology to identify assets, threats, identify and evaluate risk factors, and associate risk factor levels with different use cases identified in the product context. This security analysis informs the applicability of the technical requirements.
### C.1.1 Data
The security analysis in this Annex represents a risk assessment done by the standardisers solely for the purpose of informing the applicability of technical requirements.
#### C.1.1.1 Physical network interfaces
A list of product assets are used to identify potential threats to the product. The assumptions are used to define the scope of potential threats that are addressed by this security analysis.
Risk factor levels for each use case are determined by using the definition of the use case to choose a risk factor level that most accurately represents the highest risk for that use case. The use case is restricted by the intended purpose and reasonably foreseeable use as specified by the manufacturer.
For each threat, a formula based on the risk factor levels is used to calculate the Likelihood and Impact of the threat. This security analysis uses the Likelihood and Impact of each threat to identify specific technical requirements that treat that risk.
## B.1 Assets
### B.1.1 Data
#### B.1.1.1 Physical network interfaces
* Firmware
* Device identity (MAC address etc.)
@@ -2224,16 +2234,16 @@ Other Union legislation may be applicable to the product(s) falling within the s
* All accessible host data and functions
* Packet data
#### C.1.1.2 Virtual network interfaces or device drivers
#### B.1.1.2 Virtual network interfaces or device drivers
Risk factors determine which mitigation(s) satisfy each of the technical cybersecurity requirements in clause 5.2. The manufacturer of a product determines the level of each risk factor via the development of a threat model and risk profile based on the intended and foreseeable use and misuse of the network interface.
Risk factors determine which mitigation(s) satisfy each of the technical cybersecurity requirements in clause 5.2. The manufacturer of a product determines the level of each risk factor via its own independent risk assessment.
Risk factors may increase the likelihood of an incident, increase the impact of an incident, or both. As a result, different mitigation strategies may be more or less relevant to different risk factors.
@@ -2409,9 +2419,9 @@ Rationale: The more sensitive the functions of the product, the higher the impac
Type: Affects impact of attack.
***[SDT-L-0]** Foreseeable use is for unimportant functions
***[SDT-L-1]** Foreseeable use is for moderately sensitive functions, such as encrypting transmitted data
***[SDT-L-2]** Foreseeable use is for highly sensitive functions, such as primary management interface of host system
***[FUN-L-0]** Foreseeable use is for unimportant functions
***[FUN-L-1]** Foreseeable use is for moderately sensitive functions, such as encrypting transmitted data
***[FUN-L-2]** Foreseeable use is for highly sensitive functions, such as primary management interface of host system
**[INT]** Integration in host system
@@ -2425,27 +2435,31 @@ Type: Affects impact of attack.
***[INT-L-1]** Product is connected to host system via internal adapter requiring disassembly to change
***[INT-L-2]** Product is fully integrated into and cannot be removed from host system
## C.3 Assumptions
## B.3 Assumptions
### B.3.1 Overview
### C.3.1 Proper host system
Assumptions are used to define the scope of the potential threats addressed by this analysis.
**[AS-PH]:** The host system the product is attached to is trustworthy.
### B.3.2 Proper host system
### C.3.2 Proper administrator
The host system the product is attached to istrustworthy.
**[AS-PA]:** The product administrator is not intentionally hostile and is engaging in good faith efforts to administer the product properly.
### B.3.3 Proper administrator
### C.3.3 Attacker has limited physical access to product
The product administrator is not intentionally hostile and is engaging in good faith efforts to administer the product properly.
**[AS-LP]:** An attacker will have only temporary physical access to the product.
### B.3.4 Attacker has limited physical access to product
### C.3.4 Attacker has limited resources
An attacker will have only temporary physical access to the product.
**[AS-LR]:** An attacker has the resources available to a small group of skilled individuals, without the backing of large corporations, nation-states, or immense wealth.
### B.3.5 Attacker has limited resources
## C.4 Threats and risk assessment of threats
An attacker has the resources available to a small group of skilled individuals, without the backing of large corporations, nation-states, or immense wealth.
### C.4.1 General
## B.4 Threats and security analysis of threats
### B.4.1 General
The approach to listing threats is to separate them by mitigation so that they may be associated with mitigations more directly.
@@ -2455,7 +2469,7 @@ For the purposes of the list of threats, the product includes:
* the device driver (if any)
* the virtual network interface (if any)
### C.4.2 Risk assessment methodology
### B.4.2 Security analysis methodology
Risk factor levels for each security profile are determined by reading the descriptions for each risk factor level and choosing the one that most accurately represents the highest risk for the intended purpose and reasonably foreseeable use and misuse of the product, as specified by the manufacturer.
@@ -2475,9 +2489,9 @@ The mitigations that reduce risk by type are:
Security profiles are an informative resource to the manufacturer. Each security profile is associated with a collection of levels of risk factors. Security profiles will be mapped to specific mitigations for each cybersecurity requirements necessary to treat the risk.
### C.6.2 Mapping of security profile to risk factors
Security profiles are associated with sets of risk factor levels.
1. Do a risk assessment on the category of product covered by the new security profile.
1. Determine the risk factors for the new security profile.
1. If there are any new threats, add them to the threats list along with their risk calculation formula.
1. If any new risk factors are necessary to calculate risks for the new security profile, add the risk factors and update the score for all the security profiles.
1. Use the risk factors of the new security profile and the risk formula for each threat to calculate which of the existing mitigations must be applied.
1. After the existing risk mitigations are applied, check if all threats are sufficiently mitigated. If not, add new mitigations until the threats have been reduced sufficiently.
1. Update all relevant mappings (e.g. security profile to risk mitigation sets).
1. Propose the new security profile as a contribution to the standard.