@@ -153,6 +153,8 @@ This category includes but is not limited to:
Many products contain multiple operating systems which can affect the security functions of other operating system(s) in the product. For example, a Baseboard Management Controllers (BMC) contains an operating system that can manage most or all of the hardware managed by the main system operating system. Radiofrequency transmission devices often have an embedded real-time operating system and the ability to read or write to system memory or trigger interrupts.
Some of the operating systems may not always be readily available as separate products and are included as components of another product. Where there may be other specifications that target that product category, it may be more relevant to review the operating system as part of that larger system rather than independently via this standard.
### 1.2.2 Elements of operating systems that are in scope
The scope is limited to the security-relevant parts of the operating system. This includes any element capable of modifying elements that control the security of the system, as well as elements that provide security functionality.
@@ -546,7 +548,7 @@ _The following use cases are provided to assist manufacturers in selecting risk
* does not have accessible I/O ports
* hardware likely contains tamper-evident signals which operating system can rely on
***UC-MOB-1** A personal smart phone
***UC-MOB-1** A adult's personal mobile device
* stores highly sensitive personal information
* large number of sensors allow mass collection of sensitive personal data
* size and cost make it a common target of theft
@@ -1671,6 +1673,12 @@ The technical documentation provided with the product shall document that the op
> List any related ETSI standards and how they interact with the present document.
## B.1 Mobile Devices
The ETSI TS 103 732 series, derived from EN 303 645 and targeted to consumer mobile devices may be used to show compliance to the requirements in the present document.
> Should there be a mapping to show the relationship? Should that be to the threats, the risks, the mitigations?
# Annex C (informative): Risk identification and assessment methodology
## C.1 Assets
@@ -1771,7 +1779,7 @@ The overall risk related to each use case should be considered as a result of co
* NUSR-0: foreseeable use does not include user accounts for end-users
* NUSR-1: foreseeable use is only one user account for an end-user
f* NUSR-2: foreseeable use is primarily a single user account for an end-user authenticating, but supports multiple user accounts for end-users
* NUSR-2: foreseeable use is primarily a single user account for an end-user authenticating, but supports multiple user accounts for end-users
* NUSR-3: foreseeable use of the operating system is multiple user accounts for end-users
> FIXME: add the separate concept of users apart from accounts
@@ -2019,10 +2027,40 @@ Description: A consumer-grade home wireless router
Description: A business-grade remote door locking system
* Mobile devices generally come with the operating system pre-installed and unable to be changed to different operating system
* The operating system is generally locked down such that the user does not have access to deep control or actual administrator rights, they are limited to controls focused on user interactivity while maintaining the lower functions restricted
* While there are settings for the user to adjust, these are rarely in how the operating system itself functions, but focused on interactions at the user level
* While the device is carried around all the time and can be readily lost or stolen, the nature of the device means this is known to the user and so handled appropriately in general
* The amount of sensitive data stored and transmitted can vary, but it is expected the user would likely use the device for sensitive functions such as authentication, financial or similar services
* Network risk is high due to the use on untrusted networks
* Derived Risk Tolerance: MEDIUM (3)
Description: A child's mobile device, in a shared configuration
* Mobile devices generally come with the operating system pre-installed and unable to be changed to different operating system
* The operating system is generally locked down such that the user does not have access to deep control or actual administrator rights, they are limited to controls focused on user interactivity while maintaining the lower functions restricted
* While there are settings for the user to adjust, these are rarely in how the operating system itself functions, but focused on interactions at the user level
* As a child's device, it may be carried a lot, but is more likely to be overseen by a parent, making it less likely to be stolen
* As a child's device, it is less likely to carry as much sensitive information, as the users are not accessing sensitive services
* The child's device may have multiple accounts for different family members, or a primary account for the parents to manage the device and other accounts for the child
* Network risk is high due to the use on untrusted networks