Commit c6668be3 authored by Valerie Aurora (Bow Shock)'s avatar Valerie Aurora (Bow Shock)
Browse files

Update Annex A

parent a374ba78
Loading
Loading
Loading
Loading
+9 −7
Original line number Diff line number Diff line
@@ -1712,21 +1712,23 @@ The product shall have vulnerability handling processes compliant with <a ref="_
| CRA requirement                                 | Technical security requirements(s) |
|-------------------------------------------------|------------------------------------|
| No known exploitable vulnerabilities            | NKEV                               |
| Secure design, development, production          | MSAF                               |
| Secure design, development, production          | SSDD, LMII                         |
| Secure by default configuration                 | SDEF                               |
| Secure updates                                  | SCUD                               |
| Authentication and access control mechanisms    | _waiting on cross-vertical_        |
| Confidentiality protection                      | MISO, MSAF, CDST, CDTX             |
| Authentication and access control mechanisms    | AUTH\*                             |
| Confidentiality protection                      | MISO, LMII, CDST, CDTX, CRYP\*     |
| Integrity protection for data and configuration | MISO, IDST, IDTX                   |
| Data minimization                               | DMIN                               |
| Availability protection                         | AVAI                               |
| Minimize impact on other devices or services    | MINI                               |
| Limit attack surface                            | MISO, MSAF, LMAS                   |
| Exploit mitigation by limiting incident impact  | MISO, MIME MSAF                    |
| Availability protection                         | AVAI, LMII                         |
| Minimize impact on other devices or services    | MINI, SDEF, AVAI, SSDD, LMII       |
| Limit attack surface                            | MISO, LMAS, SSDD, LMII             |
| Exploit mitigation by limiting incident impact  | MISO, LMII, AVAI, SSDD             |
| Logging and monitoring mechanisms               | LOGG                               |
| Secure deletion and data transfer               | SCDL, SDTR                         |
| Vulnerability handling                          | VULH                               |

\* _waiting on cross-vertical_

# Annex B (informative): Relationship between the present document and any related ETSI standards (if any)

> List any related ETSI standards and how they interact with the present document.