Commit a3f14242 authored by Valerie Aurora (Bow Shock)'s avatar Valerie Aurora (Bow Shock)
Browse files

Add web browsing risk factor

parent a19bfe1b
Loading
Loading
Loading
Loading
+8 −0
Original line number Diff line number Diff line
@@ -702,6 +702,14 @@ FIXME update RF/UC chart for RF-SOFT
* FNET-2: foreseeable use includes being connected directly to the open internet
* FNET-3: foreseeable use includes being a firewall connected directly to the open internet

#### 4.5.1.N+1 Web browsing

**[RF-BRWS]:** Manufacturers of operating systems whose expected use includes browsing the web, shall implement appropriate safeguards to mitigate risks.

* FNET-0: no browser possible or foreseeable use does not include web browsing
* FNET-1: foreseeable use includes incidental or occasional web browsing
* FNET-2: foreseeable use includes web browsing as a normal activity

#### 4.5.1.12 Configurability

**[RF-CONF]:** Manufacturers of operating systems which are intended to be configurable by end users shall provide secure-by-default configurations and document all available configuration options. Such documentation shall detail any effects on safety and security that such configuration changes may cause.