The product shall reset to its secure-by-default state after a power cycle or reset command.
The product shall automatically delete all user data and settings and restore to its secure-by-default state after at least one of:
* Applicability: Product has the capability for the user to write data and/or settings
1. a power cycle, or
2. a specific reset command, or
3. a reinstallation, if necessary with a specified delete option, or
4. a specific delete command.
* Reference: ER-SCDL
#### 5.15.2.2 Applicability
* Objective: Secure deletion
TODO - has the ability to change settings or store user data
* Preparation: Document every kind of stored data or setting that may be changed by the user on the product, how to store it on the product, and how to read it from the product
### 5.15.3 REQ-DRT-03 (MI-SDRF) Secure data read from product
* Activities: For each kind of user data or setting that may be stored and changed by the user on the product, write an instance of the data or setting stored on the product that is different from the default and read it from the product; once all kinds of data have been written and read, power cycle or reset the product, and read each kind of data again
#### 5.15.3.1 Requirement
* Verdict: If any data or setting is the same for both of the reads => FAIL, otherwise => PASS
The product shall provide a method by which an authorized user can securely read all data and settings from the VPN client.
* Evidence: Record of each type of data or setting, what data or setting was written, what data or setting was returned by the first read, and what data or setting was returned by the second read, comparison of each one
#### 5.15.3.2 Applicability
#### 5.2.16.3 MI-INST: Secure deletion via reinstallation
This requirement applies to products with the capability for the user to write data and/or settings that fall within the following use cases
The product shall reset to its secure-by-default state after a reinstallation that securely deletes all previous user data or settings.
* Applicability: Product has the capability for the user to write data and/or settings
* Reference: ER-SCDL
* Objective: Secure deletion
* Preparation: Document every kind of data or setting that may be stored and changed by the user on the product, how to store it on the product, and how to read it from the product
* Activities: For each kind of user data or setting that may be stored and changed by the user on the product, write an instance of the data or setting stored on the product that is different from the default and read it from the product; once all kinds of data have been written and read, reinstall the product with the secure delete option, and read the data or settings again
* Verdict: If any data or setting is the same for both of the reads => FAIL, otherwise => PASS
* Evidence: Record of each type of data or setting, what data or setting was written, what data or setting was returned by the first read, and what data or setting was returned by the second read, comparison of each one
#### 5.2.16.4 MI-DELE: Secure deletion via secure deletion function
The product shall reset to its secure-by-default state after the secure deletion function is used.
* Applicability: Product has the capability for the user to write data and/or settings
* Reference: ER-SCDL
* Objective: Secure deletion
* Preparation: Document every kind of data or setting that may be stored and changed by the user on the product, how to store it on the product, and how to read it from the product
* Activities: For each kind of user data or setting that may be stored and changed by the user on the product, write an instance of the data or setting stored on the product that is different from the default and read it from the product; once all kinds of data have been written and read, activate the secure deletion function, and read the data or settings again
* Verdict: If any data or setting is the same for both of the reads => FAIL, otherwise => PASS
* Evidence: Record of each type of data or setting, what data or setting was written, what data or setting was returned by the first read, and what data or setting was returned by the second read, comparison of each one
#### 5.2.16.5 Mapping of mitigations to risk factors and security profiles
See clause 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
### 5.2.17 ER-SDTR: Secure data read and transfer
#### 5.2.17.1 Cybersecurity requirement
The product shall provide a method to read all data and settings from the product, and if provided, securely transfer data and settings to another product.
#### 5.2.17.2 MI-SDRF: Secure data read from product
The product shall provide a method by which an authorized user can securely read all data and settings from the product.
* Applicability: Product has the capability for the user to write data and/or settings
* Reference: ER-SDTR
* Objective: Secure data read
* Preparation: List all data and settings
* Activities: For each kind of data or setting, read the data or setting as an authorized user, then attempt read the data or setting as an unauthorized user, if any exists
* Verdict: All data and settings can be read by the authorized user, and no data or setting can be read by an unauthorized user => PASS, otherwise FAIL
* Evidence: List of data and settings, log message showing success or failure of each read by the authorized user and, if applicable, the unauthorized user
#### 5.2.17.3 MI-SDTR: Secure data transfer to another product
If the product provides a method to transfer data and settings to another product, it shall do so securely.
* Applicability: Product has the capability for the user to write data and/or settings and to transfer them to another product.
* Reference: ER-SDTR
* Objective: Secure data transfer
* Preparation: Prepare methods by which an unauthorized user could read the data during transfer as outlined in the risk assessment
* Activities: Read the data or settings, initiate the data transfer, attempt to read or alter the transferred data and settings as an unauthorized user, read the new data and settings on the target product
* Verdict: No data or settings could be read or altered by an an unauthorized user, and the data and settings read from the original product and target product are the same wherever technically possible => PASS, otherwise FAIL
* Evidence: List of data and settings, log messages from the attempts to read or alter data as the unauthorized user, data and settings as read from the source product and as read from the target product, comparison explaining technical reasons for any differences in the two versions
#### 5.2.17.4 Mapping of mitigations to risk factors and security profiles
See clause 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
TODO
## 5.3 Security Profiles
@@ -2493,6 +2414,84 @@ Otherwise FAIL
* Method of triggering events
* Logs of internal event records and/or host notifications
## 6.15 Factory reset and data portability
### 6.15.1 Overview
This clause provides assessment for the requirements in 5.15 relating to CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (m).
### 6.15.2 REQ-DRT-01 (MI-RSET) Secure deletion
#### 6.15.2.1 Objective
Secure deletion.
#### 6.15.2.2 Preparation
1. Examine the technical documentation to find every type of stored data or setting that may be changed by the user on the product, how to store it on the product, and how to read it from the product.
2. Examine the documentation accompanying the product to find how to securely delete user data and settings and reset to secure-by-default state.
#### 6.15.2.3 Activities
For each type of user data or setting that may be stored and changed by the user on the product:
1. record the value of the setting in the secure-by-default configuration of the product
2. write an instance of the data or setting stored on the product that is different from the default
Once all types of user data or settings have been written and read, use the documented method to delete all user data and settings and reset to a secure-by-default configuration. Record the value each type of user data or setting again. Compare with the original records for each type of user data or setting in its secure-by-default state.
#### 6.15.2.4 Verdict
PASS if **all** of the following are fulfilled:
* All user data and settings tested have been deleted, and
* All settings data and settings tested are restored to a secure-by-default state.
Otherwise FAIL
#### 6.15.2.5 Evidence
* List of each type of user data or setting written
* For each type, comparison of original value, written value, and value after deletion and reset to secure-by-default method
* Documentation of any differences between the original value and the value after deletion and reset
#### 6.15.2.6 Guidance
Some user settings or data (e.g. dates, randomly generated values, installation logs) may differ harmlessly between different secure-by-default configurations, so a direct comparison of the initial and final values may show some differences while passing this assessment overall.
### 6.15.3 REQ-DRT-03 (MI-SDRF) Secure data read from product
#### 6.15.3.1 Objective
Secure data read.
#### 6.15.3.2 Preparation
List all data and settings.
#### 6.15.3.3 Activities
For each type of data or setting
1. read the data or setting as an authorized user on the host system, then
2. attempt read the data or setting as an unauthorized user on the host system, if any exists.
#### 6.15.3.4 Verdict
PASS if **all** of the following are fulfilled:
* All data and settings can be read by the authorized user on the host system, and
* if any unauthorized user exists, no data or setting can be read by an unauthorized user on the host system.
Otherwise FAIL
#### 6.15.3.5 Evidence
* List of data and settings
* Log message showing success or failure of each read by the authorized user
* Log message showing success or failure of each read by the unauthorized user, if applicable
# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 - the Cyber Resilience Act
<mark>Editor's Note: Even if informative, this Annex is mandatory in Harmonised Standards.</mark>