Commit 9344b1e9 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Re-add ER-MINI after adding 5.4 (for readable diff)

parent bd687946
Loading
Loading
Loading
Loading
+31 −0
Original line number Diff line number Diff line
@@ -934,6 +934,37 @@ TODO

Only interfaces that would be exposed to unauthorized users need be disabled or protected. Which interfaces are determined by the intended purpose and reasonably foreseeble use specified by the manufacturer, and the manufacturer's risk assessment.

### 5.2.4 ER-MINI: Minimize impact on other devices and services

#### 5.2.4.1 Cybersecurity requirement

The product shall implement appropriate mitigations to minimize impact on other devices and services.

#### 5.2.4.2 MI-MDOC: Document transfer of risk of minimizing impact to operating environment

The product shall be accompanied by documentation informing the user of the transfer of risk for minimizing impact on other devices and services.

  * Reference: ER-MINI
  * Objective: Minimize impact on other devices and services
  * Activities: Examine the documentation
  * Verdict: Transfer of risk documented in a manner appropriate to the user => PASS, otherwise FAIL
  * Evidence: Documentation, analysis of documentation

#### 5.2.4.3 MI-MPHY: Prevent denial of service at physical layer

The product shall implement methods of detecting and mitigating denial of service attacks on other devices resulting from exploitation of vulnerabilities on the product via network or host system access.

  * Reference: ER-MINI
  * Objective: Minimize impact on other devices and services
  * Preparation: List known attack methods that generate output on the transmission medium originating in the product itself that negatively impact other devices and services
  * Activities: Use a tool to simulate these attacks and observe whether the product notifies the host or mitigates the negative impact itself
  * Verdict: Product notifies host or mitigates the negative impact itself  => PASS, otherwise FAIL
  * Evidence: List of attack methods, list of negative behaviours tested, log messages of product behaviour, log on host system

#### 5.2.5.8 Mapping of mitigations to risk factors and security profiles

See clause 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.

### 5.2.6 ER-SCUD: Secure updates

#### 5.2.6.1 Cybersecurity requirement