@@ -1270,6 +1270,48 @@ Guidance: This is for the use case of an end user in use cases where network acc
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
### 5.2.X **TR-SCUD**: Secure updates
#### 5.2.X.x Requirement
The product shall be securely updateable by the user.
> TODO: Waiting on completion of ETSI membership process to include detailed secure update text from an ETSI delegate. The following text is for update by the operational environment (other OS, human process, etc.).
#### 5.2.X.x **MI-SCHL**: Low security updates provided by operational environment
The technical documentation provided with the product shall document that the operational environment shall provide a method of receiving notifications of secure updates from the manufacturer, retrieving the updates, verifying the updates, and applying them to the product. The secure update method shall satisfy the "Low" security level for the product supplying it.
* Reference: TR-SCUD
* Objective: Secure updates
* Activities: Assess the documentation provided with the product
* Verdict: Documentation describes requirements for the secure updates provided by the operational environment => PASS, otherwise FAIL
* Evidence: Documentation and analysis of completeness
#### 5.2.X.x **MI-SCHM**: Medium security updates provided by operational environment
The technical documentation provided with the product shall document that the operational environment shall provide a method of receiving notifications of secure updates from the manufacturer, retrieving the updates, verifying the updates, and applying them to the product. The secure update method shall satisfy the "Medium" security level for the product supplying it.
* Reference: TR-SCUD
* Objective: Secure updates
* Activities: Assess the documentation provided with the product
* Verdict: Documentation describes requirements for the secure updates provided by the operational environment => PASS, otherwise FAIL
* Evidence: Documentation and analysis of completeness
#### 5.2.X.x **MI-SCHH**: High security updates provided by operational environment
The technical documentation provided with the product shall document that the operational environment shall provide a method of receiving notifications of secure updates from the manufacturer, retrieving the updates, verifying the updates, and applying them to the product. The secure update method shall satisfy the "High" security level for the product supplying it.
* Reference: TR-SCUD
* Objective: Secure updates
* Activities: Assess the documentation provided with the product
* Verdict: Documentation describes requirements for the secure updates provided by the operational environment => PASS, otherwise FAIL
* Evidence: Documentation and analysis of completeness
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
### 5.2.X **TR-CDST**: Confidentiality of data stored on the product
#### 5.2.X.x Requirement
@@ -1732,48 +1774,6 @@ The product shall protect the availability of essential and core network service
| LR, IoT-1 | none |
| all others | AVNT |
### 5.2.X **TR-SCUD**: Secure updates
#### 5.2.X.x Requirement
The product shall be securely updateable by the user.
> TODO: Waiting on completion of ETSI membership process to include detailed secure update text from an ETSI delegate. The following text is for update by the operational environment (other OS, human process, etc.).
#### 5.2.X.x **MI-SCHL**: Low security updates provided by operational environment
The technical documentation provided with the product shall document that the operational environment shall provide a method of receiving notifications of secure updates from the manufacturer, retrieving the updates, verifying the updates, and applying them to the product. The secure update method shall satisfy the "Low" security level for the product supplying it.
* Reference: TR-SCUD
* Objective: Secure updates
* Activities: Assess the documentation provided with the product
* Verdict: Documentation describes requirements for the secure updates provided by the operational environment => PASS, otherwise FAIL
* Evidence: Documentation and analysis of completeness
#### 5.2.X.x **MI-SCHM**: Medium security updates provided by operational environment
The technical documentation provided with the product shall document that the operational environment shall provide a method of receiving notifications of secure updates from the manufacturer, retrieving the updates, verifying the updates, and applying them to the product. The secure update method shall satisfy the "Medium" security level for the product supplying it.
* Reference: TR-SCUD
* Objective: Secure updates
* Activities: Assess the documentation provided with the product
* Verdict: Documentation describes requirements for the secure updates provided by the operational environment => PASS, otherwise FAIL
* Evidence: Documentation and analysis of completeness
#### 5.2.X.x **MI-SCHH**: High security updates provided by operational environment
The technical documentation provided with the product shall document that the operational environment shall provide a method of receiving notifications of secure updates from the manufacturer, retrieving the updates, verifying the updates, and applying them to the product. The secure update method shall satisfy the "High" security level for the product supplying it.
* Reference: TR-SCUD
* Objective: Secure updates
* Activities: Assess the documentation provided with the product
* Verdict: Documentation describes requirements for the secure updates provided by the operational environment => PASS, otherwise FAIL
* Evidence: Documentation and analysis of completeness
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
### 5.2.X Additional requirements
> TODO: Look at the [notes.md](notes.md) document for ideas for requirements to write.