@@ -1316,13 +1316,15 @@ See Section 5.3 for which mitigations are necessary for which security profiles
> TODO: Manufacturers need to contribute state-of-the-art authentication requirements. This section should reference authentication and access control standards when they exist.
### 5.2.X **TR-CDST**: Confidentiality of data stored on the product
### 5.2.7 TR-CDST: Confidentiality of data stored on the product
#### 5.2.X.x Requirement
#### 5.2.7.1 Requirement
The product shall protect data stored on the product from unauthorized access.
#### 5.2.X.x **MI-CDST**: Protect confidentiality of data stored on the product
#### 5.2.7.2 MI-CDST: Protect confidentiality of data stored on the product
> TODO: This is a blanket mitigation that is too vague and high-level. Manufacturers need to contribute more detailed and specific mitigations.
The product shall protect data stored on the product from unauthorized access.
@@ -1340,25 +1342,19 @@ The product shall protect data stored on the product from unauthorized access.
Guidance: Data may be protected by the environment, permissions, encryption, salting and hashing, offline storage, or hardware-backed secrets.
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles
| Risk factors | Requires mitigations |
|--------------|----------------------|
| SNDS < 1 | none |
| all others | CDST |
#### 5.2.7.3 Mapping of mitigations to risk factors and security profiles
| Security Profile | Requires mitigations |
|------------------|----------------------|
| LR, IoT-1 | none |
| all others | CDST |
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
### 5.2.X **TR-CDTX**: Confidentiality of data transmitted by product
### 5.2.8 TR-CDTX: Confidentiality of data transmitted by product
#### 5.2.X.x Requirement
#### 5.2.8.1 Requirement
The product shall protect data transmitted by the product from unauthorized access.
#### 5.2.X.x **MI-CDTX**: Protect confidentiality of data transmitted by product
#### 5.2.8.2 MI-CDTX: Protect confidentiality of data transmitted by product
> TODO: This is a blanket mitigation that is too vague and high-level. Manufacturers need to contribute more detailed and specific mitigations.
The product shall protect data transmitted by the product from unauthorized access.
@@ -1376,29 +1372,35 @@ The product shall protect data transmitted by the product from unauthorized acce
Guidance: Data transmitted may be protected by the environment or encryption.
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles
#### 5.2.8.3 MI-DOCC: Document transfer of risk of confidentiality of data transmitted by product
| Risk factors | Requires mitigations |
|--------------|----------------------|
| SNDT < 1 | none |
| all others | CDTX |
The product shall be accompanied by documentation informing the user of the transfer of risk for protecting the confidentiality of data transmitted by the product.
| Security Profile | Requires mitigations |
|------------------|----------------------|
| FIXME | none |
| all others | CDTX |
* Reference: TR-CDTX
* Objective: Protect data confidentiality
* Activities: Examine the documentation
* Verdict: Transfer of risk documented in a manner appropriate to the user => PASS, otherwise FAIL
* Evidence: Documentation, analysis of documentation
> TODO: Rate use cases by sensitivity of data transmitted and update the security profile list above.
#### 5.2.8.4 Mapping of mitigations to risk factors and security profiles
### 5.2.X **TR-IDST**: Integrity of data stored on the product
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
#### 5.2.X.x Requirement
### 5.2.9 TR-CRYP: Encryption
> TODO: Fill in very limited encryption requirements that are not performance-related (this is probably remote management and self-update). Need to specify any necessary encryption algorithms that are not already included in the Agreed Cryptographic Mechanism and CRA Addendum.
### 5.2.10 TR-IDST: Integrity of data stored on the product
#### 5.2.10.1 Requirement
The product shall protect the integrity of data stored on the product from unauthorized modification and report corruption.
Guidance: Integrity may be protected by the environment, permissions, duplication, backups, and/or checksums.
#### 5.2.X.x **MI-IDST**: Protect integrity of data stored on the product
#### 5.2.10.2 MI-IDST: Protect integrity of data stored on the product
> TODO: This is a blanket mitigation that is too vague and high-level. Manufacturers need to contribute more detailed and specific mitigations.
The product shall protect the integrity of data stored on the product from unauthorized modification.
@@ -1414,7 +1416,9 @@ The product shall protect the integrity of data stored on the product from unaut
* Evidence: Logs of determination of type of data and method of integrity and attempts to modify protected data without authorization
#### 5.2.X.x **MI-DCST**: Detect corruption of data stored
#### 5.2.10.3 MI-DCST: Detect corruption of data stored
> TODO: This is a blanket mitigation that is too vague and high-level. Manufacturers need to contribute more detailed and specific mitigations.
The product shall detect corruption of the data stored on the product.
@@ -1430,31 +1434,21 @@ The product shall detect corruption of the data stored on the product.
* Evidence: Logs of determination of type of data and corruptions of data
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles
| Risk factors | Requires mitigations |
|--------------|----------------------|
| SNDS < 1 | none |
| SNDS < 2 | IDST |
| all others | IDST, DCST |
#### 5.2.10.4 Mapping of mitigations to risk factors and security profiles
| Security Profile | Requires mitigations |
|------------------|----------------------|
| LR, IoT-1 | none |
| MOB-1 | IDST, DCST |
| all others | IDST |
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
> TODO: Rate use cases by sensitivity of data stored and update the security profile list above.
### 5.2.11 TR-IDTX: Integrity of data transmitted by the product
### 5.2.X **TR-IDTX**: Integrity of data transmitted by the product
#### 5.2.X.x Requirement
#### 5.2.11.1 Requirement
The product shall detect corruption of the data transmitted by the product.
Guidance: Integrity may be protected by the environment, permissions, duplication, backups, and/or checksums.
#### 5.2.X.x **MI-DCTX**: Detect corruption of data transmitted by the product
#### 5.2.11.2 MI-DCTX: Detect corruption of data transmitted by the product
> TODO: This is a blanket mitigation that is too vague and high-level. Manufacturers need to contribute more detailed and specific mitigations.
The product shall detect corruption of the data transmitted by the product.
@@ -1466,23 +1460,13 @@ The product shall detect corruption of the data transmitted by the product.
* Activities: For each type of data and method of detecting corruption, corrupt the data in a way that the method will detect
* Verdict: If all methods of detecting corruption match the type of the data stored, and all the corruptions of data are detected => PASS, otherwise => FAIL
* Verdict: If all methods of detecting corruption match the type of the data transmitted, and all the corruptions of data are detected => PASS, otherwise => FAIL
* Evidence: Logs of determination of type of data and corruptions of data
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles
#### 5.2.11.3 Mapping of mitigations to risk factors and security profiles
| Risk factors | Requires mitigations |
|--------------|----------------------|
| SNDT < 1 | none |
| all others | DCTX |
| Security Profile | Requires mitigations |
|------------------|----------------------|
| LR, IoT-1 | none |
| all others | DCTX |
> TODO: Rate use cases by sensitivity of data transmitted and update the security profile list above.
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.