Commit b2c3f58c authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Annex B.1/B.2: Update data assets and assumptions

Most notably add hardware assets and refine threat actor resources
assumption.
parent e8585194
Loading
Loading
Loading
Loading
+23 −20
Original line number Diff line number Diff line
@@ -2126,6 +2126,8 @@ Other Union legislation may be applicable to the product(s) falling within the s

# Annex B (informative): Security analysis 

## B.0 Overview

This Annex applies state of the art methodology to identify assets, threats, identify and evaluate risk factors, and associate risk factor levels with different use cases identified in the product context. This security analysis informs the applicability of the technical requirements.

The security analysis in this Annex represents a risk assessment done by the standardisers solely for the purpose of informing the applicability of technical requirements.
@@ -2140,24 +2142,17 @@ For each threat, a formula based on the risk factor levels is used to calculate

### B.1.1 Data

#### B.1.1.1 Physical network interfaces

* Firmware
* Firmware/software
* Device identity (MAC address etc.)
* Device configuration (transmit power/channel configuration/options)
* Statistics
* Security keys for validation of access to itself (firmware, management access)
* Security keys for packet encryption or network access
* Device driver stored on device, if any
* Metrics
* Cryptographic material for validation of access to itself (firmware, management access)
* Cryptographic material for packet encryption or network access
* Device driver shipped with device or stored on device, if any
* All accessible host data and functions
* Packet data

#### B.1.1.2 Virtual network interfaces or device drivers

* Data transmitted over the network
* Data transmitted to the host system
* Device driver executable
* Interface configuration
* Statistics
* Security keys

### B.1.2 Product functions

@@ -2173,7 +2168,7 @@ Optional:
* Offload of packet processing at layers higher than data link
* Packet encryption at data link layer
* Packet encryption at higher layer
* Keep and report network statistics
* Keep and report metrics
* Update firmware with image provided by host
* Manage firmware update autonomously (image received from the network)
* Provide remote management interface
@@ -2181,8 +2176,9 @@ Optional:

### B.1.2.2 Device driver essential functions

* Interact with operating system
* Copy data between network device interface and host memory
* Handle interrupts, set up tx/rx, keep/copy statistics, etc.
* Handle interrupts, set up tx/rx, keep/copy metrics, etc.
* Configure the network interface
* Monitor device interface and network interface health
* Interact with operating system and user programs
@@ -2191,7 +2187,7 @@ Optional:

* Set up and execute firmware update/load with image provided by host software
* Support optional features of the underlying device hardware or software
* Provision keys to device (network access, management, packet encryption)
* Provision cryptographic material to device (network access, management, packet encryption)
* Generate log messages
* Use debug interfaces

@@ -2200,15 +2196,22 @@ Optional:
* Process/move around data sent to virtual network interface
* Interact with operating system
* Configure the network interface
* Keep and report network statistics
* Keep and report metrics
* Read/write/etc host resources accessible from virtual network interface

Optional:

* Packet encryption
* Provision keys (network access, management, packet encryption)
* Provision cryptographic material (network access, management, packet encryption)
* Generate log messages

### B.1.3 Hardware

* Physical transmission media interface
* Connection to host system
* Processors
* Memory

## B.2 Risk factors

### B.2.1 List of risk factors
@@ -2301,7 +2304,7 @@ An attacker will have only temporary physical access to the product.

### B.3.5 Attacker has limited resources

An attacker has the resources available to a small group of skilled individuals, without the backing of large corporations, nation-states, or immense wealth.
An attacker will use limited resources in proportion to the value of the assets of the product in each use case.

## B.4 Threats and security analysis of threats