Commit c2f6eb53 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Add Clause 5.13/6.13 Exploit mitigations

Use the exploit mitigations requirement from VPN with modifications.
parent 22ebb838
Loading
Loading
Loading
Loading
+23 −0
Original line number Diff line number Diff line
@@ -1126,6 +1126,21 @@ Exposure of interfaces on the product shall be minimised in its secure-by-defaul

TODO

## 5.13 Exploit mitigation

### 5.13.1 Overview

This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (k).

### 5.13.2 Requirements

The following requirements address this essential cybersecurity requirement:

* REQ-ALC-01 (MI-FZ95, MI-BTIN) Resilience to potentially untrusted inputs
* REQ-AP-04 (MI-WDOG): Watchdog and self-initiated reset
* REQ-AP-05 (MI-NTFY): Watchdog and notification of host
* REQ-MON-01 (MI-LOGG): Logging

### 5.2.15 ER-LOGG: Logging and monitoring

#### 5.2.15.1 Cybersecurity requirement
@@ -2254,6 +2269,14 @@ Otherwise FAIL

See Clause \[6.1.2\] "Guidance for identifying interfaces or data processing."

## 6.13 Exploit mitigation

### 6.13.1 Overview

This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (k).

No additional assessment is necessary for the requirements in this clause, as the included requirements are assessed in other clauses of the present document.

# Annex A (informative): Relationship between the present document and the CRA

<mark>Editor's Note: Even if informative, this Annex is mandatory in Harmonised Standards.</mark>