Commit a374ba78 authored by Valerie Aurora (Bow Shock)'s avatar Valerie Aurora (Bow Shock)
Browse files

Add vulnerability handling requirement

parent fb86e2b9
Loading
Loading
Loading
Loading
+18 −0
Original line number Diff line number Diff line
@@ -1680,6 +1680,23 @@ If the product provides a method to transfer data and settings to another produc

See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.

### 5.2.18 TR-VULH: Vulnerability handling

#### 5.2.18.1 Requirement

The product shall have vulnerability handling processes compliant with <a ref="_ref_3">[3] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Vulnerability Handling".

#### 5.2.18.2 MI-VULH: Vulnerability handling

The product shall have vulnerability handling processes compliant with <a ref="_ref_3">[3] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Vulnerability Handling".

  * Applicability: (for requirements that depend on a feature)
  * Reference: TR-VULH
  * Objective: Vulnerability handling
  * Activities: Review documentation associated with vulnerability handling.
  * Verdict: Vulnerability handling documentation is compliant with <a ref="_ref_3">[3] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Vulnerability Handling" => PASS, otherwise FAIL
  * Evidence: Vulnerability handling documentation, comparison with <a ref="_ref_3">[3] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Vulnerability Handling"

## 5.3 Risk Mitigation Sets

> TODO: Connect the technical security requirements in clause 5.2 to specific Risk Factors, and define these as sets of Risk Mitigations that will be referenced in clause 6.
@@ -1708,6 +1725,7 @@ See Section 5.3 for which mitigations are necessary for which security profiles
| Exploit mitigation by limiting incident impact  | MISO, MIME MSAF                    |
| Logging and monitoring mechanisms               | LOGG                               |
| Secure deletion and data transfer               | SCDL, SDTR                         |
| Vulnerability handling                          | VULH                               |

# Annex B (informative): Relationship between the present document and any related ETSI standards (if any)