Commit d8d231ba authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Update Clause 3 Definitions to revised structure

closes #38
parent 3e0223e3
Loading
Loading
Loading
Loading
+43 −13
Original line number Diff line number Diff line
@@ -172,9 +172,16 @@ The following referenced documents may be useful in implementing an ETSI deliver

## 3.1 Terms

For the purposes of the present document, the following terms apply:
For the purposes of the present document, the terms given in Regulation (EU) 2024/2847 [\[i.1\]](#_ref_i.1), prEN 40000-1-1 [\[i.4\]](#_ref_i.4) and the following apply:

<mark>Editor's Note: A definition of term should be such that it can replace the term in context. Any additional information shall be given only in the form of examples or notes. (see ETSI Directives section EDRs, clause 2.11.1).</mark>

<mark>Editor's Note: Proposal to put together a common term sheet for all verticals developed in CYBER-EUSR.</mark>

<mark>Editor’s Note: For ease of reading, it is possible to quote the definitions of Regulation (EU) 2024/2847. Use of quotation marks is mandatory in such a case.</mark>

<mark>Editor’s Note: The standard should not do legal interpretation by defining some key legal concepts of Regulation (EU) 2024/2847. Notably, the standard should not define “core functionality” or “due diligence”.</mark>

NOTE:	This clause provides terms and definitions based on CEN/CLC JTC13 WG09's [i.6] work on terms and definitions, terms and definitions provided by ETSI TS 103 701 [i.5], prEN 40000-1-1[i.6], and by CEN/CLC EN 18031 [i.2] series.
**Cybersecurity requirement:** A requirement described within this standard to conform to the \"Essential requirements\" of the Cyber Resilience Act [i.1] 

**device driver:** piece of software or firmware running on the host that enables communication on the network via the network interface
@@ -207,28 +214,48 @@ NOTE: This clause provides terms and definitions based on CEN/CLC JTC13 WG09's [

**wireless network interface:** physical network interface which transmits data in a manner that does not require a specific medium, such as radiofrequency waves or visible light communication through the air

## 3.2 Abbreviations
## 3.2 Symbols

<mark> Editor's Note: choose one of the three following lines, whichever applies most appropriately. Replace ... with your reference.</mark>

For the purposes of the present document, the following symbols apply:

For the purposes of the present document, the symbols given in ... apply:

For the purposes of the present document, the symbols given in ... and the following apply:

## 3.3 Abbreviations

For the purposes of the present document, the following abbreviations apply:

`ADEF  Authoriztion Required by Default`    
<mark>Editor's Note: The following is a list of abbreviations used in some of the CRA vertical standards. It is not complete yet.</mark>

<mark>Editor's Note: Please only keep the abbreviations that are used in the present document and avoid using the same abbreviation with different meaning in the CRA vertical standards.</mark>

`ACM   Agreed Cryptographic Mechanisms`  
`ADEF  Authorization Required by Default`    
`ADM   Availability and Skill of Administration`  
`API   Application Programming Interface`  
`AHHS  Harm to Host System Via Unauthorized Access Through the Network`  
`AS    Assumption`  
`AUTH  Authentication`  
`AVAI  Availability`  
`BTIN  Boundry Testing of Inputs`  
`BTIN  Boundary Testing of Inputs`  
`CDST  Confidentiality of Stored Data`  
`CDTX  Confidentiality of Transmitted Data`  
`CEN   Comité Européen de Normalisation`  
`COM   Complexity of Product Functions`  
`CONF  Configuration (Errors)`  
`CRA   Cyber Resilience Act`  
`CYRP  Encryption`  
`CRYP  Encryption`  
`CPU   Central Processing Unit`  
`CRA   Cyber Resilience Act`  
`CVE   Common Vulnerabilities and Exposures`  
`DCTX  Detect Corruption of Transmitted Data`  
`DCST  Detect Corruption of Storedd Data`  
`DCST  Detect Corruption of Stored Data`  
`DDOS  Denial of Service (Attack)`   
`DECT  Digital Enhanced Cordless Telecommunications`  
`DECT2020 NR  Digital Enhanced Cordless Telecommunications New Radio Plus`  
`DELE  Secure Deletion Via Secure Delete Function`     
`DJST  Document and Justify Processed Data`   
`DMIN  Data Minimization`   
@@ -237,12 +264,12 @@ For the purposes of the present document, the following abbreviations apply:
`DPAH  Documentation of Product Assets Accessible from Host`    
`ER    Essential Security Requirement`  
`FAIR  Fair Resource Usage and Prioritization`  
`FDRP  Fast PAcket Drop`  
`FDRP  Fast Packet Drop`  
`FUN   Sensitivity of Functions`  
`IDST  Integrity of Stored Data`    
`IDTX  Integrity of Transmitted Data`  
`IMSL  Implement in Memory Safe Language` 
`INST  Secure Deleation Via Reinstallation`
`INST  Secure Deletion Via Reinstallation`
`INT   Integration in Host System`  
`IoT   Internet of Things`
`ISP   Internet Service Provider`  
@@ -273,6 +300,7 @@ For the purposes of the present document, the following abbreviations apply:
`NTFY  Watchdog and Notification of Host`    
`OS    Operating System`  
`OT    Operational Technology`  
`PC    Personal Computer`  
`PCIe  Peripheral Component Interconnect Express`  
`PDDI  Protect, Document, or Disable Interface`  
`PDOS  Denial of Service Attack on Product Functions`  
@@ -280,18 +308,20 @@ For the purposes of the present document, the following abbreviations apply:
`PHYS  Acquistion of Physical Product`  
`PII   Personally Identifiable Information`  
`PXE   Preboot Execution Environment`  
`RDPS  Remote Data Processing Solution`  
`ROM   Read Only Memory`     
`RSET  Secure Deleation Via Reset`       
`RSET  Secure Deletion Via Reset`  
`RTOS  Real Time Operating System`     
`SBOM  Software Bill of Materials`  
`SCAN  No Easily Scannable Vulnerabilities`
`SCDL  Secure Deleation`
`SCDL  Secure Deletion`  
`SCFS  Secure Completion Flags`   
`SCUD  SEcure Updates`   
`SCUD  Secure Updates`   
`SDEF  Secure Default Configuration`
`SDS   Sensitivity of Data Stored`  
`SDRF  Secure Data Read From Product`  
`SDT   Sensitivity of Data Transfered`  
`SDTR  Secure Data Rea and Transfer`  
`SDTR  Secure Data Read and Transfer`  
`SFT   Sensitivity of Data Stored`  
`SSCA  Static Source Code Analysis`  
`SSDD  Secure Design and Development`