Commit d988e84a authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Clause 5.3/B.5: Remove security profiles

Security profiles are dead, long live use cases!
parent 3d4b1c14
Loading
Loading
Loading
Loading
+4 −310
Original line number Diff line number Diff line
@@ -1319,278 +1319,6 @@ This requirement applies to products with the capability for the user to write d

TODO

## 5.3 Security Profiles

This clause lists all the mitigations necessary to meet cybersecurity requirements for each security profile. 

### 5.3.1 Introduction

Security profiles in the context of this document are an intermediary tool that connects specific cybersecurity technical requirement and thier associated mitigations with product use cases. 
Each security profile below applies to one or more use case and includes a list of technical requirements and mitigations that are necessary to secure the products described by the use case.
It is worth noting that neither security profiles or use cases constitute exhuastive lists and that they do not include mitigations intended to provide guidance on due diligence for components or product functions performed by non-RDPS remote services.

To apply a security profile to a specific product the manufacturer shall implement the technical requirements and mitigations it containes per clause 5.2 of this document and need not implement technical requirements or mitigations unlisted in the security profile.
For some security profiles products are given the option to apply one or more from a list of related technical requirments and mitigations based on the functions, implementation, security constraints, and what is most secure and practicable for the specific product.
This option is noted by the use of "or" between technical requirements and mitigations listed in the security profile, or in cases where there are technical requirements with multiple mitigations, this is noted by the same alphabetic abbreviation followed by a "-\*" to indicate that any for the mitigations may be utilized to satisfy the technical requirement.

Security profiles are abbreviated with a set of letters and numbers denoting their general characteristics.
This abbreviation begins with "SP" to indicate that the abbreviation describes a security profile and is followed by another two letters indicating if the profile is for a wired interface ("WD"), wireless interface ("WL"), or virtual interface ("VI").
Finally, the abbreviation includes a number to indicate it with greater specificity, with higher numbers generally indicating security profiles of greater complexity.  

Use cases, as described in clause 4.7 above, are mapped to appropriate security profile by reference to the table in Annex C.5.2 

### 5.3.1 Wired network interface risk mitigation sets

#### 5.3.1.1 SP-WD-1 required mitigations

1. SCFS
1. SUDC
1. (SUVP or SUAP or SUOE or SUAO)
1. DJST
1. (NTFY or WDOG)
1. DOST
1. LOGG

#### 5.3.1.2 SP-WD-2 required mitigations

1. (KEVD or KEVA or KEVT or SCAN)
1. SCFS
1. SSCA
1. (FZ95 or BTIN or IMSL)
1. IMSL or (MSAF-\*, MZRO-\*)
1. ADEF
1. DPAH
1. PDDI-1
1. PDDI-4
1. SUDC
1. (SUVP or SUAP or SUOE or SUAO)
1. AUTH
1. CDST
1. DCTX
1. DJST
1. NTFY
1. WDOG
1. FDRP
1. LMEM
1. FAIR
1. DOST
1. MDOC
1. MPHY
1. JSTY
1. LOGG
1. VULH

#### 5.3.1.3 SP-WD-3 required mitigations

1. (KEVD or KEVA or KEVT or SCAN)
1. SCFS
1. SSCA
1. (FZ95 or BTIN or IMSL)
1. IMSL or (MSAF-\*, MZRO-\*)
1. ADEF
1. DPAH
1. PDDI-1
1. PDDI-4
1. SUDC
1. (SUVP or SUAP or SUOE or SUAO)
1. AUTH
1. CDST
1. DCTX
1. DJST
1. (NTFY or WDOG)
1. LMEM
1. DOST
1. MDOC
1. MPHY
1. JSTY
1. LOGG
1. VULH

#### 5.3.1.4 SP-WD-4 required mitigations

1. (KEVD or KEVA or KEVT or SCAN)
1. SCFS
1. SSCA
1. (FZ95 or BTIN or IMSL)
1. IMSL or (MSAF-\*, MZRO-\*)
1. ADEF
1. DPAH
1. PDDI-\*
1. SUDC
1. (SUVP or SUAP or SUOE or SUAO)
1. AUTH
1. CDST
1. CDTX
1. DOCC
1. DCTX
1. DJST
1. NTFY
1. WDOG
1. FDRP
1. LMEM
1. FAIR
1. DOST
1. MDOC
1. MPHY
1. JSTY
1. LOGG
1. VULH

### 5.3.2 Wireless network interface risk mitigation sets

#### 5.3.2.1 SP-WL-1 required mitigations

1. (KEVD or KEVA or KEVT or SCAN)
1. SCFS
1. SSCA
1. IMSL or (MSAF-\*, MZRO-\*)
1. ADEF
1. DPAH
1. PDDI-1
1. SUDC
1. (SUVP or SUAP or SUOE or SUAO)
1. AUTH
1. CDST
1. DOCC
1. IDST
1. DCTX
1. DJST
1. (NTFY or WDOG)
1. LMEM
1. DOST
1. MDOC
1. JSTY
1. LOGG
1. (RSET or INST or DELE)
1. SDRF
1. VULH

#### 5.3.2.2 SP-WL-2 required mitigations

1. AUTH
1. KEVD
1. KEVA
1. (KEVT or SCAN)
1. SCFS
1. SSCA
1. (FZ95 or BTIN or IMSL)
1. IMSL or (MSAF-\*, MZRO-\*)
1. ADEF
1. DPAH
1. PDDI-1
1. PDDI-4
1. SUDC
1. (SUAP or SUAO)
1. AUTH
1. CDST
1. CDTX
1. DOCC
1. IDST
1. DCTX
1. DJST
1. (NTFY or WDOG)
1. LMEM
1. MDOC
1. MPHY
1. DOST
1. JSTY
1. LOGG
1. (RSET or INST or DELE)
1. SDRF
1. VULH

#### 5.3.2.3 SP-WL-3 required mitigations

1. AUTH
1. KEVD
1. KEVA
1. (KEVT or SCAN)
1. SCFS
1. SSCA
1. (FZ95 or BTIN or IMSL)
1. IMSL or (MSAF-\*, MZRO-\*)
1. ADEF
1. DPAH
1. PDDI-\*
1. SUDC
1. (SUAP or SUAO)
1. AUTH
1. CDST
1. CDTX
1. DOCC
1. IDST
1. DCTX
1. DJST
1. (NTFY or WDOG)
1. LMEM
1. DOST
1. MDOC
1. MPHY
1. JSTY
1. LOGG
1. (RSET or INST or DELE)
1. SDRF
1. VULH

### 5.3.3 Virtual network interface risk mitigation sets

#### 5.3.3.1 SP-VI-1 required mitigations

1. (KEVD or KEVA or KEVT or SCAN)
1. SCFS
1. IMSL or (MSAF-\*, MZRO-\*)
1. SUDC
1. (SUVP or SUAP or SUOE or SUAO)
1. CDST
1. IDST
1. DCTX
1. DJST
1. (NTFY or WDOG)
1. LMEM
1. DOST
1. JSTY
1. LOGG
1. SDRF
1. VULH

#### 5.3.3.2 SP-VI-2 required mitigations

1. AUTH
1. KEVD
1. KEVA
1. (KEVT or SCAN)
1. SCFS
1. SSCA
1. (FZ95 or BTIN or IMSL)
1. IMSL or (MSAF-\*, MZRO-\*)
1. ADEF
1. DPAH
1. PDDI-1
1. PDDI-3
1. PDDI-4
1. SUDC
1. (SUAP or SUAO)
1. AUTH
1. CDST
1. IDST
1. DCST
1. DCTX
1. DJST
1. NTFY
1. WDOG
1. FDRP
1. LMEM
1. FAIR
1. MDOC
1. MPHY
1. DOST
1. JSTY
1. LOGG
1. (RSET or INST or DELE)
1. SDRF
1. SDTR
1. VULH

# 6 Conformity Assessment

## 6.1 General
@@ -2802,7 +2530,7 @@ For the purposes of the list of threats, the product includes:

### B.4.2 Security analysis methodology

Risk factor levels for each security profile are determined by reading the descriptions for each risk factor level and choosing the one that most accurately represents the highest risk for the intended purpose and reasonably foreseeable use and misuse of the product, as specified by the manufacturer.
Risk factor levels for each use case are determined by reading the descriptions for each risk factor level and choosing the one that most accurately represents the highest risk for the intended purpose and reasonably foreseeable use and misuse of the product, as specified by the manufacturer.

For each threat, a formula based on the risk factor levels is used to calculate the Likelihood and Impact of the threat, on a scale of Low, Medium, and High.

@@ -3102,43 +2830,9 @@ Mitigations for Likelihood:

* High to Low: AUTH

### B.5.2 Mapping of use cases to risk factors and security profiles

#### B.5.2.1 Wired network interface use cases

| Use case | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT | Sec Pro |
|----------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|---------|
| UC-WD-1  | 0   | 0   | 0   | 1   | 2   | 0   | 0   | 0   | 0   | 1   | 2   | SP-WD-1 |
| UC-WD-2  | 0   | 0   | 0   | 1   | 0   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-1 |
| UC-WD-3  | 0   | 0   | 1   | 1   | 0   | 0   | 1   | 0   | 1   | 2   | 1   | SP-WD-2 |
| UC-WD-4  | 0   | 0   | 2   | 1   | 0   | 0   | 2   | 0   | 1   | 2   | 1   | SP-WD-2 |
| UC-WD-5  | 0   | 0   | 2   | 1   | 1   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-2 |
| UC-WD-6  | 1   | 1   | 1   | 1   | 0   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-3 |
| UC-WD-7  | 1   | 1   | 1   | 1   | 2   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-3 |
| UC-WD-8  | 1   | 1   | 2   | 1   | 2   | 0   | 1   | 0   | 1   | 1   | 1   | SP-WD-3 |
| UC-WD-9  | 0   | 2   | 1   | 1   | 0   | 0   | 2   | 0   | 1   | 2   | 1   | SP-WD-4 |
| UC-WD-10 | 2   | 2   | 1   | 1   | 1   | 0   | 2   | 0   | 0   | 0   | 1   | SP-WD-4 |

#### B.5.2.2 Wireless network interface use cases

| Use case | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT | Sec Pro |
|----------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|---------|
| UC-WL-1  | 0   | 0   | 0   | 2   | 0   | 0   | 1   | 1   | 1   | 1   | 1   | SP-WL-1 |
| UC-WL-2  | 0   | 0   | 1   | 2   | 2   | 1   | 0   | 0   | 0   | 1   | 2   | SP-WL-1 |
| UC-WL-3  | 0   | 0   | 2   | 2   | 0   | 1   | 2   | 1   | 1   | 1   | 1   | SP-WL-2 |
| UC-WL-4  | 1   | 1   | 2   | 2   | 0   | 2   | 2   | 1   | 1   | 1   | 1   | SP-WL-2 |
| UC-WL-5  | 0   | 1   | 1   | 2   | 2   | 1   | 1   | 1   | 1   | 1   | 1   | SP-WL-2 |
| UC-WL-6  | 1   | 1   | 2   | 2   | 2   | 2   | 2   | 1   | 1   | 1   | 1   | SP-WL-3 |
| UC-WL-7  | 2   | 2   | 1   | 2   | 1   | 2   | 1   | 0   | 0   | 0   | 1   | SP-WL-3 |

#### B.5.2.3 Virtual network interface use cases

| Use case | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT | Sec Pro |
|----------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|---------|
| UC-VI-1  | 0   | 1   | 0   | 0   | 0   | 0   | 0   | 1   | 1   | 1   | 0   | SP-VI-1 |
| UC-VI-2  | 0   | 1   | 2   | 2   | 2   | 0   | 1   | 1   | 1   | 1   | 0   | SP-VI-2 |
| UC-VI-3  | 0   | 1   | 1   | 2   | 0   | 0   | 2   | 2   | 2   | 2   | 0   | SP-VI-2 |
| UC-VI-4  | 0   | 2   | 2   | 2   | 0   | 0   | 2   | 2   | 2   | 2   | 0   | SP-VI-2 |
### B.5.2 Mapping of use cases to risk factors

TODO

# Annex K (normative): Generic cryptographic requirements and assessment