@@ -529,252 +529,301 @@ Indirect users of network interfaces include:
## 4.6 Use Cases
### 4.6.1 Overview
#### 4.6.1.1 Overview
Use cases are defined in terms of risk factor levels that determine which requirements in Clause 5 must be satisfied to reduce the cybersecurity risks of the product to an acceptable level.
The purpose of a use case is to create defined sets of technical requirements (Clause 5) that may be used to treat the risks found by the manufacturer's independent cybersecurity risk analysis.
The manufacturer designates an intended purpose for the product. This intended purpose and its reasonably foreseeable use may be used to select a use case with risks that are fully treated by the associated requirements.
Use cases are defined by their risk factor levels. The risk factor levels are used by the informative Security Analysis in Annex B to select the group of technical requirements associated with that use case.
While it is possible to list every possible combination of risk factor levels, the use cases addressed in this section are intended to represent useful and common categories of products.
Specific use cases are identified by their use case IDs, which are constructed in the following manner:
New use cases may be added along with any new risk factors or requirements necessary to fully treat the risks.
**UC-\[XX\]-\[YYY\]**
### 4.6.1 Wired network interface use cases
Where "XX" is either "PH" for physical network interface or "VI" for virtual network interface, and "YYY" is three letters that serve to remind the reader of one or more examples.
#### 4.6.1.1 UC-WD-1 Wired stationary home IoT device
#### 4.6.1.2 Guidance
* Goal: Connect a home appliance to a home network for local control and monitoring
It is not necessary to find a use case whose risks are identical to those identified by the product's cybersecurity risk assessment. If a use case has equal or higher risks to the product's, then it can be used. For example, a use case that includes the product being connected to a public netork (a high level of this risk factor) can also be used for a product whose intended purpose is to be connected to a private network with a filtered connection to a public network.
New use cases may be added to the present document along with any new risk factors or requirements necessary to fully treat the risks.
Any use case for an end product can be converted to an integrator use case by copying it and setting the RF-INI value to 0.
## 4.6.2 Use case descriptions
#### 4.6.2.1 UC-VI-ISO: Virtual interface for research within a host system
* Goal: Simulate networking for research or development
* Description:
* Examples: Network interfaces in thermostat, fridge
* Product type: Wired network interface
* Function: Connect host system to local private network, simple data transfer
* Goal: Connect professional device to a filtered private network
* Goal: Allow remote management of devices
* Description:
* Examples: Network interfaces in switches behind edge firewall devices
* Product type: Wired network interface
* Function: Connect host system to a filtered private network
* Examples: 5G in vending machine to service electronic payments, report
* Product type: Physical network interface
* Physical access: Public
* Function: Allow management of device
* Complexity: Medium
* Host system impact: Medium
* User administration skill: High
*Operational environment: Moderate sensitivity device connected in location accessible by authorized users only
*Initial setup environment: Access-controlled
#### 4.6.1.4 UC-WD-4 Wired professional edge device or internet infrastructure
#### 4.6.2.4 UC-PH-IOT: Physical network interface for home IoT
* Goal: Connect professional device to public internet
* Goal: Connect a home appliance to a home network for local control and monitoring
* Description:
* Examples: Network interfaces in firewalls, VPN servers, switches in IXPs and ISPs, smart meter gateways and data concentrators in a smart metering system
* Product type: Wired network interface
* Function: Connect host system to a public network
* Complexity: Medium
* User administration skill: High
* Operational environment: High sensitivity device connected to public network in access-controlled area
* Examples: Smart lightbulb bluetooth module, ethernet module for coffee machines
* Product type: Physical network interface
* Physical access: Home
* Function: Connect low sensitivity device to local private network for management
* Complexity: High
* Host system impact: Low
* User administration skill: Low (high risk)
* Initial setup environment: Access-controlled
#### 4.6.1.5 UC-WD-5 Wired stationary home gateway
#### 4.6.2.5 UC-PH-IRO: Intranet router
* Goal: Connect home network to public network
* Goal: Connect to routers and devices in intranet
* Description:
* Examples: Network interfaces in ISP-manage access point
* Product type: Wired interface
* Function: Connect and filter data from a public network to a private home network
* Complexity: Medium
* User administration skill: High (remotely managed by ISP staff)
* Operational environment: Low sensitivity devices connected to public network in private home
* Examples: Line cards in an intranet router for enterprise office intranet
* Product type: Physical network interface
* Physical access: Access-controlled
* Function: Connect intranet devices and routers
* Complexity: High
* Host system impact: Low
* User administration skill: High
* Initial setup environment: Access-controlled
#### 4.6.1.6 UC-WD-6 Wired professional worker device on internal network
#### 4.6.2.6 UC-PH-EDG: Edge router
* Goal: Connect stationary professional device to filtered private network and public network
* Goal: Provide connection and filtering to public network
* Description:
* Examples: Network interfaces in stationary personal computer, registration terminal, cash register
* Product type: Wired network interface
* Function: Connect host system to a filtered private network
* Complexity: Medium
* Examples: Line cards in an edge router for enterprise office intranet
* Product type: Physical network interface
* Physical access: Access-controlled
* Function: Connect intranet with public network
* Complexity: High
* Host system impact: Medium
* User administration skill: High
*Operational environment: Medium sensitivity device connected to filtered private network and public network in public area
*Initial setup environment: Access-controlled
#### 4.6.1.7 UC-WD-7 Wired stationary home device
#### 4.6.2.7 UC-PH-HRO: Home router in filtered network
* Goal: Connect home device to a public network
* Goal: Connect home devices and internet access point
* Description:
* Examples: Network interfaces in stationary personal computer, IoT hub, thermostat, TV
* Product type: Wired network interface
* Function: Connect host system to a public network
* Complexity: Medium
* Examples: Ethernet and wifi modules in home router behind ISP access point
* Product type: Physical network interface
* Physical access: Home
* Function: Connect devices to each other in filtered private network
* Complexity: High
* Host system impact: Low
* User administration skill: Low
*Operational environment: Medium sensitivity device connected to public network via firewall in private home
*Initial setup environment: Access-controlled
#### 4.6.1.8 UC-WD-8 Wired mobile device
#### 4.6.2.8 UC-PH-ISP: ISP access point
* Goal: Connect mobile general purpose computing device to public network temporarily via wired connection
* Goal: Provide connection and filtering to public network
* Description:
* Examples: Network interfaces in laptop
* Product type: Wired network interface
* Function: Connect host system to a public network
* Complexity: Medium
* User administration skill: Low
* Operational environment: Medium sensitivity device connected to public network via firewall in private home
* Examples: Cable modem or fiber card in ISP access point
* Product type: Physical network interface
* Physical access: Home
* Function: Connect home network with public network
* Complexity: High
* Host system impact: Low
* User administration skill: Medium (mix of professional and amateur)
* Initial setup environment: Access-controlled
#### 4.6.1.9 UC-WD-9 Wired stationary public server
#### 4.6.2.9 UC-VI-VDC: Virtualize data center
* Goal: Connect server with multiple untrusted users to a public network
* Goal: Connect VMs in data center to each other and public network
* Description:
* Examples: Network interfaces in shared webhosting
* Product type: Wired network interface
* Function: Connect host system to a public network
* Examples: Emulated interfaces in a business's data processing cluster
* Product type: Virtual network interface
* Physical access: None
* Function: Share hardware, connect to filtered private network
* Complexity: Medium
* Host system impact: High
* User administration skill: High
*Operational environment: Medium sensitivity device connected to public network via firewall in access-controlled area
*Initial setup environment: Access-controlled
#### 4.6.1.10 UC-WD-10 Wired stationary device for public use
#### 4.6.2.10 UC-VI-VMW: VM on multi-tenant web server
* Goal: Connect public use device to public network via firewall
* Goal: Connect VMs in web server to public network
* Description:
* Examples: Network interfaces in public library computer, vending machine
* Product type: Wired network interface
* Function: Connect host system to a public network
* Examples: Virtual interface in container for shared web hosting provider
* Product type: Virtual network interface
* Physical access: None
* Function: Share hardware, connect to public network
* Complexity: Medium
* Host system impact: High
* User administration skill: High
*Operational environment: Low sensitivity device connected to public network via firewall in public area
*Initial setup environment: Access-controlled
### 4.6.2 Wireless network interface use cases
#### 4.6.2.11 UC-VI-VMC: Virtualize critical server
#### 4.6.2.1 UC-WL-1 Wireless professional device in isolated internal infrastructure
* Goal: Connect VMs running critical infrastructure to public network
* Description:
* Examples: Virtual interface in guest VM for banking infrastructure
* Product type: Virtual network interface
* Physical access: None
* Function: Share hardware, connect to public network
* Complexity: Medium
* Host system impact: High
* User administration skill: High
* Initial setup environment: Access-controlled
* Goal: Connect professional device to isolated network
#### 4.6.2.12 UC-VI-VII: Virtual interface for integrators
* Goal: Provide virtual interfaces to developers of products
* Description:
* Examples: Network interfaces in data centre for internal job processing, smart meter in an isolated private network
* Product type: Wireless network interface
* Function: Connect host system to a isolated network
* Examples: Virtio network driver in virtual machine, loopback for containers
* Product type: Virtual network interface
* Physical access: None
* Function: Share hardware, connect to public network
* Complexity: High
* Host system impact: High
* User administration skill: High
*Operational environment: Medium sensitivity device connected to isolated network in access-controlled area
*Initial setup environment: Access-controlled
#### 4.6.2.2 UC-WL-2 Wireless stationary home IoT device
#### 4.6.2.13 UC-PH-SMW: Smart watch
* Goal: Connect stationary home device to public internet via firewall
* Goal: Connect small mobile devices to larger mobile devices
* Description:
* Examples: Network interfaces in lightbulb, smart oven, stationary personal computer
* Product type: Wireless network interface
* Function: Connect host system to a public network via firewall
* Function: Connect wirelessly to public network via nearby trusted device
* Complexity: High
* Host system impact: High/Medium/Low
* User administration skill: Low
*Operational environment: Medium sensitivity device connected to public network via firewall in private home
*Initial setup environment: Access-controlled
#### 4.6.2.3 UC-WL-3 Wireless professional edge device or internet infrastructure
#### 4.6.2.14 UC-PH-SME: Smart meter
* Goal: Connect professional device to public internet
* Goal: Connect infrastructure device to server
* Description:
* Examples: Network interfaces in firewalls, VPN servers, switches in IXPs and ISPs, smart meter gateways and data concentrators in a smart metering system
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Examples: Energy smart meter/data concentrator PLC connection, water or gas meters wMBUS connection, NBIoT connection, LoRaWAN connection, handy terminal to read meter data wMBUS connection, parking meter Bluetooth, etc.
* Product type: Physical network interface
* Physical access: Public
* Function: Transmit device data to private server via private or public network
* Complexity: High
* Host system impact: High
* User administration skill: High
*Operational environment: High sensitivity device connected to public network in access-controlled area
*Initial setup environment: Access-controlled
#### 4.6.2.4 UC-WL-4 Wireless mobile enterprise worker device
#### 4.6.2.15 UC-PH-ATM: ATM
* Goal: Connect mobile general purpose computing device to public internet
* Goal: Connect public infrastructure device to public network
* Description:
* Examples: Network interfaces in company laptop, phone, tablet
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Examples: ATM ethernet module, traffic camera LoRaWAN module
* Product type: Physical network interface
* Physical access: Public
* Function: Connect infrastructure to filtered network to public network
* Complexity: High
* Host system impact: High
* User administration skill: High
*Operational environment: Medium sensitivity device connected to public network via firewall in public area
*Initial setup environment: Access-controlled
#### 4.6.2.5 UC-WL-5 Wireless stationary home device
#### 4.6.2.16 UC-PH-SPI: Solar panel inverter
* Goal: Connect home device to a public network
* Goal: Connect critical infrastructure device to server
* Description:
* Examples: Network interfaces in stationary personal computer, IoT hub, thermostat, TV
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Examples: Solar panel inverter wifi, water pump LoRaWAN, meter data concentrator WAN connection
* Product type: Physical network interface
* Physical access: Semi-private
* Function: Remote management of critical OT devices
* Complexity: High
* User administration skill: Low
* Operational environment: Medium sensitivity device connected to public network via firewall in private home
* Host system impact: High
* User administration skill: High
* Initial setup environment: Access-controlled
#### 4.6.2.6 UC-WL-6 Wireless mobile personal device
#### 4.6.2.17 UC-VI-VPN: Consumer VPN
* Goal: Connect mobile general purpose computing device to public network
* Goal: Encrypt/route traffic
* Description:
* Examples: Network interfaces in laptop, phone, tablet, watch
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Examples: Consumer VPN client, VPN interface in remotely managed power strip
* Product type: Virtual network interface
* Physical access: None
* Function: Provide secure tunnel across public networks
* Complexity: High
* Host system impact: High
* User administration skill: Low
*Operational environment: Medium sensitivity device connected to public network via firewall in public area
*Initial setup environment: Home
#### 4.6.2.7 UC-WL-7 Wireless stationary device for public use
#### 4.6.2.18 UC-PH-MOB: Mobile phone or tablet
* Goal: Connect public use device to public network via firewall
* Goal: Connect high importance mobile device to public networks
* Description:
* Examples: Network interfaces in public library computer, vending machine
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Examples: 5G modem in phone, Wifi/bluetooth module in tablet
* Product type: Physical network interface
* Physical access: Public
* Function: Connect to public network via local wireless
* Complexity: High
* User administration skill: High
* Operational environment: Low sensitivity device connected to public network via firewall in public area
### 4.6.3 Virtual network interface use cases
#### 4.6.3.1 UC-VI-1 Virtual network interface for internal use on private or professional device
* Goal: Connect software within a host system
* Description:
* Examples: Network interfaces in loopback, containers, tunnel to local application
* Product type: Virtual network interface
* Function: Connect software within a single host
* Complexity: Low
* User administration skill: High
* Operational environment: Medium sensitivity software connected to isolated network within single host
* Host system impact: High
* User administration skill: High/Medium/Low
* Initial setup environment: Access-controlled
#### 4.6.3.2 UC-VI-2 Virtual network interface for external use on private device
#### 4.6.2.19 UC-PH-GPI: General purpose integrated
* Goal: Connect software to public networks indirectly
* Goal: Connect server/desktop/laptop computer to public network
* Description:
* Examples: Network interfaces for virtio on hypervisors, VPN interfaces, tunnel interfaces
* Product type: Virtual network interface
* Function: Connect software to a public network
* Examples: Ethernet on motherboard on server, pre-installed wifi card on laptop
* Product type: Physical network interface
* Physical access: Access-controlled/Home/Public
* Function: Individuals accessing the public internet
* Complexity: High
* Host system impact: High
* User administration skill: Low
*Operational environment: Medium sensitivity device connected to public network in access-controlled area
*Initial setup environment: Access-controlled
#### 4.6.3.3 UC-VI-3 Virtual network interface for external use on enterprise device
#### 4.6.2.20 UC-PH-USB: External USB
* Goal: Connect software to public networks indirectly
* Goal: Connect computer to public network
* Description:
* Examples: Network interfaces for virtio on hypervisors, VPN interfaces, tunnel interfaces
* Product type: Virtual network interface
* Function: Connect software to a public network
* Examples: USB ethernet dongle, USB wifi dongle
* Product type: Physical network interface
* Physical access: Public
* Function: Provide access to public network from a computer
* Complexity: High
* User administration skill: High
* Operational environment: High sensitivity device connected to public network in access-controlled area
* Host system impact: Medium
* User administration skill: Low
* Initial setup environment: Public
#### 4.6.3.4 UC-VI-4 Virtual network interface for external use on public server
#### 4.6.2.21 UC-PH-STA: Standalone
* Goal: Connect software to public networks indirectly
* Goal: User installs into server/laptop/desktop/etc.
* Description:
* Examples: Network interfaces for virtio on hypervisors, VPN interfaces, tunnel interfaces
* Product type: Virtual network interface
* Function: Connect arbitrary user software to a public network
* Examples: PCIe ethernet card for server, wifi/bluetooth module for laptop
* Product type: Physical network interface
* Physical access: Public
* Function: Provide access to public network from a computer
* Complexity: High
* User administration skill: High
* Operational environment: High sensitivity device connected to public network in access-controlled area
* Host system impact: High
* User administration skill: Low
* Initial setup environment: Public
# 5 Technical requirements for the Products
@@ -2668,7 +2717,29 @@ Mitigations for Likelihood:
### B.5.2 Mapping of use cases to risk factors
TODO
| Use case | PHY | NET | FUN | SYS | COM | ADM | INI |