@@ -349,9 +349,37 @@ For the purposes of the present document, the following abbreviations apply:
# 4 Product context
## 4.1 Intended purpose and reasonably foreseeable use
<mark>Editor's Note: This clause shall not contain technical cybersecurity requirements. For instance, it should not start describing the desirable security features that a product should have. It should also not contain normative language (no “shall”), or even recommendations (the use of “should” should be limited to the extent possible). This clause serves to define the intended purpose and foreseeable use of the products and flesh out the concept of what constitutes the product with digital elements to help with determining applicability. </mark>
The intended purpose and reasonably foreseeable use of this product is to provide communication between computer systems over a network, whether physical or virtual.
<mark>Editor’s Note: RDPS are explicitly identified in the product context. RDPS interfaces and trust boundaries are described in the product architecture overview. RDPS assumptions and constraints are reflected in the operational environment description. Where relevant, dependencies on third party cloud solutions are included in the distribution of security functions.</mark>
## 4.0 Introduction
<mark>Editor’s note: this Introduction Clause is optional, used for any introductory text/sentence to avoid hanging paragraphs.</mark>
A virtual or physical network interface enables the connection of a computing device to a network. A network interface provides connectivity via a device driver API operating at the data link layer.
Physical network interfaces are products that directly connect a device to a network via an application programming interface (API) provided by device drivers. This connection may be wired or wireless and feature hardware adapters to transmission media with corresponding firmware, typically physical network interfaces operate at the physical and data link layer.
Products that are connected to a host system by a communications bus, such as PCIe or USB are physical network interfaces, though they may use a wide variety of technologies to enable this connection including both direct physical connections and wireless connections.
The category of physical network interfaces is broad and composed of wired and wireless network interface cards, controllers and adapters, and network interface hardware modules, such as for Wi-Fi™, Ethernet, cellular modems, DECT and DECT2020 NR modems, IrDA, USB, Bluetooth®, NearLink, Zigbee®, Fieldbus, or Infiniband.
Virtual network interfaces are products that directly or indirectly connect a device to a network via an API that emulates that of device drivers or physical network interfaces, typically operating at the data link layer. These virtual network interfaces consist of software running on a host system, and communicate via the device driver interface of that host.
As purely virtual, standalone products, a virtual network interface remains a product whose core function is that of a network interface and that provides a remote management interface for the network interface or the host system.
Examples of virtual network interfaces also include: container network interfaces, VPN interfaces, and loopback interfaces.
For the purposes of the present document, network interfaces will be split up into the following groups, due to their distinct threat models:
* Wired network interfaces
* Wireless network interfaces
* Virtual network interfaces
Network interfaces are closely related to what is commonly called a \"modem\", but this general term is used for two different kinds of products:
1.\"Modem interface\": A single network interface that connects a physical transmission adapter to a system bus, as for example a 5G modem interface or Power Line Communication device
2.\"Standalone modem\": A device with two or more network interfaces that routes network data between two different networks, relaying data from one type of physical transmission media to another, such as a cable modem
\"Modem interfaces\" are included in the present document. \"Standalone modems\" are excluded from the present document, but may be found in the vertical CRA standard for Routers Modems & Switches [i.9]