The manufacturer shall minimize exposed interfaces in the default configuration of the product in all operating modes, including initial configuration, during initialization, while in use, while shutting down or paused, or after reset.
#### 5.2.X.x **MI-JSTY**: Document and justify exposed interfaces
@@ -1659,6 +1673,8 @@ All exposed interfaces on the product in any state that is part of its reasonabl
### 5.2.X **TR-SCDL**: Secure deletion
### 5.2.X.x Requirement
The product shall provide a method of deleting all data and settings and resetting the product to its secure-by-default configuration.
Guidance: Overwriting all storage or encrypting all data and deleting the key are two secure deletion mechanisms.
@@ -1727,6 +1743,8 @@ The product shall reset to its secure-by-default state after the secure deletion
### 5.2.X **TR-SDTR**: Secure data read and transfer
### 5.2.X.x Requirement
The product shall provide a method to read all data and settings from the product, and if provided, securely transfer data and settings to another product.
#### 5.2.X.x **MI-SDRF**: Secure data read from product
@@ -1777,6 +1795,8 @@ The product shall provide a method by which an authorized user can securely tran
### 5.2.X **TR-DMIN**:
### 5.2.X.x Requirement
The product shall minimize the data processed.
#### 5.2.X.x **MI-DJST**: Document and justify processed data
@@ -1812,6 +1832,8 @@ All sources of data processed by the product in its secure-by-default configurat
### 5.2.X **TR-SCUD**: Secure updates
### 5.2.X.x Requirement
The product shall be securely updateable by the user.
> FIXME: Waiting on legal approval to include self-update text, following text is for update by the operational environment (other OS, human process, etc.)