{"packId":"en-304-623","packVersion":"0.1.0","standard":{"reference":"ETSI EN 304 623","title":"CYBER; CRA; Essential cybersecurity requirements for boot managers","status":"INTERIM DRAFT — ETSI open consultation; subject to substantial change before publication (target: second half of 2026). Not cited in the Official Journal: conformance confers NO presumption of conformity today.","sourceUrl":"https://labs.etsi.org/rep/stan4cra/en-304-623","sourceCommit":"b1611ce6","retrievedAt":"2026-09-02","license":"BSD-3-Clause, © 2025 ETSI. Redistributed with attribution as the license requires; the verbatim requirement and assessment text below is reproduced from the interim draft.","licenseText":"Copyright 2025 ETSI\n\nRedistribution and use in source and binary forms, with or without\nmodification, are permitted provided that the following conditions are met:\n1. Redistributions of source code must retain the above copyright notice,\n   this list of conditions and the following disclaimer.\n2. Redistributions in binary form must reproduce the above copyright notice,\n   this list of conditions and the following disclaimer in the documentation\n   and/or other materials provided with the distribution.\n3. Neither the name of the copyright holder nor the names of its contributors\n   may be used to endorse or promote products derived from this software without\n   specific prior written permission.\n\nTHIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS \"AS IS\" AND\nANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED\nWARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.\nIN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,\nINDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,\nBUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,\nDATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF\nLIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE\nOR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED\nOF THE POSSIBILITY OF SUCH DAMAGE."},"appliesTo":{"craCategory":"important-1","annexIIIItem":"Boot managers","note":"Attaches to a product whose CRA classification matched the Annex III boot managers item, or manually."},"scope":"## 1.1 General\n\nThe present document specifies technical cybersecurity product requirements for boot managers based on the Essential Cybersecurity Requirements in the Regulation (EU) 2024/2847 (Cyber Resilience Act).\n\nThe scope covers software and firmware components that manage the boot process from power-on through establishment of the chain of trust to handoff to the boot target.\n\nRequirements apply using a risk-based approach determined by risk factors in clause 4.7.8 and capability-based conditions defined in clause 4.3.3.\n\n## 1.2 In-scope products\n\nProducts in scope include are boot management software and firmware regardless of distribution model or integration level. These are:\n\n- **System firmware** that performs hardware initialisation and boot management\n- **Bootloaders** that manage boot target selection, verification, and loading\n- **Embedded boot firmware** in IoT and embedded devices\n- **Network boot implementations** enabling remote boot capabilities\n- Boot managers that **integrate with hardware security components** for chain of trust establishment\n\nNOTE 1: Boot managers may be single-stage (direct loading) or multi-stage (staged verification).\n\nNOTE 2: For microcontrollers (MCUs) and microprocessors (MPUs):\n\n- **Silicon-integrated immutable firmware**: Mask ROM, fused code, or boot firmware integrated during chip manufacturing is assessed as part of MCU/MPU hardware under semiconductor standards.\n- **Updateable boot managers**: Boot software in flash storage (including OTP programmed post-manufacture) is assessed using this standard when distinctly identifiable or independently updatable.\n\nNOTE 3: Runtime services executing after boot target handoff (such as secure monitor mode handlers or attestation services) are in scope only if they provide verification or attestation services to the boot process itself, not to the boot target.","applicabilityIntro":"This clause establishes cybersecurity requirements implementing Annex I Part I and Part II of Regulation (EU) 2024/2847.\n\nRequirements apply based on risk level (LOW, MEDIUM, HIGH) derived from deployment context assessment per clause 4.7.8, ensuring cybersecurity measures are proportionate to identified risks and fit for purpose. Product capabilities (verified boot, updatability, configuration capability, etc.) determine additional applicability conditions. Each requirement explicitly specifies its applicability.\n\nRequirements address boot manager security properties including initial trust establishment without prior security infrastructure, operation under resource constraints, and protection against persistent compromise.","useCases":[{"id":"UC-L1","title":"Immutable embedded","description":"Boot manager in isolated devices with no update capability and fixed configuration. Code is immutable after manufacture.\n\n**Examples**: Environmental sensors, simple embedded controllers, basic IoT sensors, electronic toys, ROM-based microcontrollers.\n**Capabilities**: No updates, no configuration, no logging, no recovery."},{"id":"UC-L2","title":"Updateable IoT and consumer","description":"Boot manager in connected consumer devices with update capability and basic configuration. Limited security features appropriate for non-sensitive applications.\n\n**Examples**: Smart TVs, gaming consoles, smart home devices, e-readers, consumer appliances, development boards.\n**Capabilities**: Updates, basic configuration, optional: verified boot, logging."},{"id":"UC-M1","title":"Consumer and SMB computing","description":"Boot manager in general-purpose computing devices storing personal or business data. Verified boot and logging enable security monitoring.\n\n**Examples**: Laptops, desktops, tablets, smartphones, small business servers, NAS devices, connected vehicles.\n**Capabilities**: Verified boot, logging, configuration, updates. Optional: recovery, authentication."},{"id":"UC-M2","title":"Enterprise managed","description":"Boot manager in enterprise infrastructure under centralised management. Full management suite enables policy enforcement and attestation.\n\n**Examples**: Enterprise workstations, servers, network infrastructure, virtualisation hosts, managed endpoints.\n**Capabilities**: Verified boot, measured boot, network boot, logging, configuration, authentication, recovery. Optional: hardware security storage."},{"id":"UC-H1","title":"Critical systems","description":"Boot manager in systems where compromise causes safety impact, critical service disruption, or severe data breach. Maximum security controls with hardware enforcement.\n\n**Examples**: Medical devices, industrial control systems, financial infrastructure, government systems, telecommunications infrastructure, critical facility management.\n**Capabilities**: Full suite including hardware security storage and hardware security enforcement.\n\nNOTE: UC-H1 includes varied deployment contexts (connected vs isolated, healthcare vs industrial). Manufacturers conduct detailed risk assessment per clause 4.7.8 based on specific deployment."}],"craMap":[{"craRef":"Annex I, Part I, (1)","clauses":"4.7.7, 4.7.8, 5.1, 5.2"},{"craRef":"Annex I, Part I, (2)(a)","clauses":"5.12.1, 5.12.2, 6.1"},{"craRef":"Annex I, Part I, (2)(b)","clauses":"5.3"},{"craRef":"Annex I, Part I, (2)(c)","clauses":"5.6.4, 5.12.2, 5.12.8"},{"craRef":"Annex I, Part I, (2)(d)","clauses":"5.3.2, 5.4"},{"craRef":"Annex I, Part I, (2)(e)","clauses":"5.5"},{"craRef":"Annex I, Part I, (2)(f)","clauses":"5.6"},{"craRef":"Annex I, Part I, (2)(g)","clauses":"5.7"},{"craRef":"Annex I, Part I, (2)(h)","clauses":"5.8"},{"craRef":"Annex I, Part I, (2)(i)","clauses":"5.9"},{"craRef":"Annex I, Part I, (2)(j)","clauses":"5.10"},{"craRef":"Annex I, Part I, (2)(k)","clauses":"5.2.3, 5.9"},{"craRef":"Annex I, Part I, (2)(l)","clauses":"5.11"},{"craRef":"Annex I, Part I, (2)(m)","clauses":"5.5.7, 5.5.8"},{"craRef":"Annex I, Part II, (1)","clauses":"5.12.1, 6.1"},{"craRef":"Annex I, Part II, (2)","clauses":"5.6.4, 5.12.2, 5.12.8"},{"craRef":"Annex I, Part II, (3)","clauses":"6.1"},{"craRef":"Annex I, Part II, (4)","clauses":"5.12.2"},{"craRef":"Annex I, Part II, (5)","clauses":"5.12"},{"craRef":"Annex I, Part II, (6)","clauses":"5.12.1, 5.12.2"},{"craRef":"Annex I, Part II, (7)","clauses":"5.6.4, 5.12.7, 5.12.9, 5.12.10"},{"craRef":"Annex I, Part II, (8)","clauses":"5.12.2"}],"topics":[{"clause":"5.2","title":"Security by Design","overview":"This subclause addresses CRA requirements for secure design, development, and production. Boot manager security architecture need to integrate protective measures from initial design through implementation, considering pre-OS constraints, limited resources, and critical boot integrity requirements. This clause implements the principle of security by design as defined in prEN 40000-1-2.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-SBD-001","requirement":"The boot manager shall isolate boot components using memory protection, privilege separation, or hardware isolation mechanisms available on platform.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-SBD-002","requirement":"The boot manager shall restrict access to cryptographic key material to authorised boot components as defined by the boot manager's security policy.","applicability":{},"applicabilityText":"Applies to all boot managers with cryptographic keys.","assessment":null},{"id":"RQ-SBD-003","requirement":"The boot manager shall, before boot target handoff: disable debug interfaces, revoke DMA-capable device access, release hardware resources, free allocated memory, clear network buffers, and restrict memory regions to those required by the boot target.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-SBD-004","requirement":"The boot manager shall enforce privilege boundaries preventing privilege escalation between boot stages or across trust boundaries.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null}]},{"clause":"5.3","title":"Secure by Default Configuration","overview":"This subclause addresses CRA requirements for secure default configuration. Boot managers shall be put on the market with security features enabled, no default credentials, and protection matching available hardware and software resources. This clause implements the principle of secure by default as defined in prEN 40000-1-2.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-DEFAULT-001","requirement":"The boot manager shall enable cryptographic signature validation by default.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-DEFAULT-002","requirement":"The boot manager shall not contain any default passwords, maintenance backdoors, or undocumented access methods.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-DEFAULT-003","requirement":"The boot manager shall require credentials to be established during initial deployment when using password authentication.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability using password authentication.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-DEFAULT-004","requirement":"The boot manager shall prevent automatic fallback to less secure boot modes.","applicability":{},"applicabilityText":"Applies to all boot managers with verified or measured boot.","assessment":null},{"id":"RQ-DEFAULT-005","requirement":"The boot manager shall provide user-visible indication when security is being reduced.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-DEFAULT-006","requirement":"The boot manager shall support restoration of secure defaults.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}}]},{"clause":"5.4","title":"Authentication and Authorisation","overview":"This subclause addresses CRA requirements for access control and authentication. Boot managers control code execution authorisation and configuration protection through cryptographic verification, physical presence detection, and hardware-based protections.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-AUTH-001","requirement":"The boot manager shall require physical presence for changes to trusted keys, certificates, or trust anchor databases.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level HIGH. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-AUTH-002","requirement":"The boot manager shall protect boot order and boot parameters from unauthorised modification.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-AUTH-003","requirement":"The boot manager shall require explicit user action and authentication before weakening secure defaults, downgrading security settings, or modifying security-critical options.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-AUTH-004","requirement":"The boot manager shall limit authentication attempts with increasing delays between failed attempts where passwords are used.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability using password authentication.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level MEDIUM. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-AUTH-005","requirement":"The boot manager shall verify digital signatures of boot security configuration policies before application.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot and configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level MEDIUM. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-AUTH-006","requirement":"The boot manager shall indicate when running with modified policies through persistent visual indication or logged events.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}}]},{"clause":"5.5","title":"Confidentiality","overview":"This subclause addresses CRA requirements for data confidentiality. Boot managers shall protect cryptographic key material, credentials, and security policies in resource-constrained environments against persistent physical access threats.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-CONFID-001","requirement":"The boot manager shall maintain separate key material for verification, encryption, and decryption operations.","applicability":{},"applicabilityText":"Applies to all boot managers with verified or measured boot.","assessment":null},{"id":"RQ-CONFID-002","requirement":"The boot manager shall protect trusted certificate stores from unauthorised modification.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-CONFID-003","requirement":"The boot manager shall exclude sensitive data from crash dumps and logs.","applicability":{},"applicabilityText":"Applies to all boot managers with logging capability.","assessment":null},{"id":"RQ-CONFID-004","requirement":"The boot manager shall hash stored credentials including user passwords and recovery keys.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration and recovery capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level MEDIUM. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-CONFID-005","requirement":"The boot manager shall encrypt network boot parameters containing authentication information in storage.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability and network boot.","assessment":null},{"id":"RQ-CONFID-006","requirement":"The boot manager shall exclude cryptographic keys and mask partial key material or authentication tokens from all logs.","applicability":{},"applicabilityText":"Applies to all boot managers with logging capability.","assessment":null},{"id":"RQ-CONFID-007","requirement":"The boot manager shall cryptographically erase all sensitive data and clear all user-enrolled keys and certificates during secure disposal.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot and configuration capability.","assessment":null},{"id":"RQ-CONFID-008","requirement":"The boot manager shall indicate successful sanitisation completion when secure disposal is supported.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-CONFID-009","requirement":"The boot manager shall protect the confidentiality of boot configuration data transmitted over network.","applicability":{},"applicabilityText":"Applies to all boot managers with network boot.","assessment":null},{"id":"RQ-CONFID-010","requirement":"The boot manager shall overwrite sensitive data after use, clear temporary data structures and credentials before boot target handoff, and not persist authentication credentials or cryptographic material beyond the current boot cycle.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null}]},{"clause":"5.6","title":"Integrity Protection","overview":"This subclause addresses CRA requirements for data and system integrity. Boot managers establish trust chains through cryptographic verification, measurement, and protection mechanisms that resist component substitution, rollback, and TOCTOU attacks.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-INTEGRITY-001","requirement":"The boot manager shall verify integrity and authenticity of each boot stage using cryptographic hashes and digital signatures, establishing chain of trust to a root trust anchor before transferring control.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-002","requirement":"The boot manager shall prevent boot continuation with unverified components and reject components with invalid, expired, revoked, or substituted signatures.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-003","requirement":"The boot manager shall verify component provenance through certificates and check component compatibility and version consistency.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-004","requirement":"The boot manager shall verify authenticity and integrity of update packages before installation and after network transfer.","applicability":{},"applicabilityText":"Applies to all boot managers with update capability.","assessment":null},{"id":"RQ-INTEGRITY-005","requirement":"The boot manager shall detect unauthorised firmware modifications using at least two distinct verification mechanisms; use software-based cryptography with protected storage when hardware security components are unavailable.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-006","requirement":"The boot manager shall maintain a configurable list of approved signatures.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot and configuration capability.","assessment":null},{"id":"RQ-INTEGRITY-007","requirement":"The boot manager shall support multiple signature formats.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-008","requirement":"The boot manager shall require authentication before allowing verification bypass.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-009","requirement":"The boot manager shall prevent unauthorised modification between verification and execution.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-INTEGRITY-010","requirement":"The boot manager shall load components into protected memory before verification.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-011","requirement":"The boot manager shall execute verification checks atomically preventing TOCTOU vulnerabilities.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-012","requirement":"The boot manager shall protect sensitive configuration settings with authenticated encryption.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level MEDIUM. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-INTEGRITY-013","requirement":"The boot manager shall restore secure defaults when configuration corruption is detected.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-INTEGRITY-014","requirement":"The boot manager shall prevent unauthorised runtime modification of boot code.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-INTEGRITY-015","requirement":"The boot manager shall authenticate network boot servers using cryptographic certificates.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with network boot.","assessment":null},{"id":"RQ-INTEGRITY-016","requirement":"The boot manager shall reject network boot connections with invalid, expired, or revoked server certificates.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with network boot.","assessment":null},{"id":"RQ-INTEGRITY-017","requirement":"The boot manager shall verify DHCP and PXE responses originate from authorised infrastructure.","applicability":{},"applicabilityText":"Applies to all boot managers with network boot.","assessment":null},{"id":"RQ-INTEGRITY-018","requirement":"The boot manager shall enforce rollback protection for firmware and security configuration by default.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with update or configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level MEDIUM. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-INTEGRITY-019","requirement":"The boot manager shall store anti-rollback counters in hardware-backed or tamper-evident storage and verify signed version metadata before accepting updates.","applicability":{},"applicabilityText":"Applies to HIGH risk boot managers with update capability.","assessment":null},{"id":"RQ-INTEGRITY-020","requirement":"The boot manager shall support hierarchical trust with separate manufacturer and owner trust domains, owner-installable certificates, and certificate authority transitions during ownership changes.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with verified boot and configuration capability.","assessment":null},{"id":"RQ-INTEGRITY-021","requirement":"The boot manager shall verify the entire certificate chain to a trusted root, including validity periods and revocation status.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-022","requirement":"The boot manager shall support revocation of compromised keys and certificates through a revocation database or configuration updates.","applicability":{},"applicabilityText":"Applies to all boot managers with verified boot.","assessment":null},{"id":"RQ-INTEGRITY-023","requirement":"The boot manager shall use cryptographic algorithms, key sizes, and parameters listed in ECCG Agreed Cryptographic Mechanisms [2] or demonstrably equivalent state-of-the-art mechanisms..","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-INTEGRITY-024","requirement":"The boot manager shall support cryptographic algorithm updates through updateable trust anchors or multiple algorithm support.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with update capability.","assessment":null}]},{"clause":"5.7","title":"Data Minimisation","overview":"This subclause addresses CRA requirements for data minimisation. Boot managers shall process only data necessary for boot operations, security verification, and error indication, given memory and storage constraints.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-MINIMAL-001","requirement":"The boot manager shall minimise network disclosure by requesting only necessary files, negotiating only required protocol parameters, and exposing only MAC address and device class.","applicability":{},"applicabilityText":"Applies to all boot managers with network boot.","assessment":null},{"id":"RQ-MINIMAL-002","requirement":"The boot manager shall not disclose firmware version, hardware serial numbers, or internal configuration in network protocols, and shall not retain network credentials beyond use.","applicability":{},"applicabilityText":"Applies to all boot managers with network boot.","assessment":null},{"id":"RQ-MINIMAL-003","requirement":"The boot manager shall store only essential boot parameters, security policy settings, and boot device priorities in configuration storage.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":null}]},{"clause":"5.8","title":"Availability and Resilience","overview":"This subclause addresses CRA requirements for availability and resilience. Boot managers shall maintain availability during failures or attacks through recovery mechanisms, failsafe operations, and resistance to denial-of-service conditions.\n\nNOTE: Where this subclause specifies limits without numeric values, the manufacturer shall document specific thresholds in security documentation per Annex C. Assessors verify defined and enforced limits.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-AVAIL-001","requirement":"The boot manager shall support fallback to previous known-good configuration.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":null},{"id":"RQ-AVAIL-002","requirement":"The boot manager shall automatically recover from corrupted configuration data.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":null},{"id":"RQ-AVAIL-003","requirement":"The boot manager shall support redundant boot paths.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers.","assessment":null},{"id":"RQ-AVAIL-004","requirement":"The boot manager shall indicate which boot image is currently active when multiple images are maintained.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with update capability.","assessment":null},{"id":"RQ-AVAIL-005","requirement":"The boot manager shall enforce timeouts for all operations including parsing and network operations, preventing indefinite hangs.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-AVAIL-006","requirement":"The boot manager shall limit retry attempts and resource consumption for signature verification and network operations.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-AVAIL-007","requirement":"The boot manager shall not allow security verification steps to be skipped.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-AVAIL-008","requirement":"The boot manager shall detect and correct errors in critical data.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers.","assessment":null},{"id":"RQ-AVAIL-009","requirement":"The boot manager shall store essential boot code redundantly.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers.","assessment":null},{"id":"RQ-AVAIL-010","requirement":"The boot manager shall verify critical structures through checksums.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-AVAIL-011","requirement":"The boot manager shall require authentication or physical presence for recovery mode.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with recovery capability.","assessment":null},{"id":"RQ-AVAIL-012","requirement":"The boot manager shall handle network boot failures by implementing timeouts with local fallback, exponential backoff retries, multiple server options, and maintain local boot capability under denial-of-service conditions.","applicability":{},"applicabilityText":"Applies to all boot managers with network boot.","assessment":null},{"id":"RQ-AVAIL-013","requirement":"The boot manager shall generate logs of security failure conditions protected against tampering through cryptographic binding, hardware security components, or write-once storage.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with verified boot or measured boot.","assessment":null},{"id":"RQ-AVAIL-014","requirement":"The boot manager shall use time representations for certificates, internal time, and timestamps that remain valid beyond 2038.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-AVAIL-015","requirement":"The boot manager shall protect recovery mechanisms from unauthorised modification or disablement.","applicability":{},"applicabilityText":"Applies to all boot managers with recovery capability.","assessment":null},{"id":"RQ-AVAIL-016","requirement":"The boot manager shall, on security or verification failure: halt boot, maintain integrity, prevent partial execution, and not attempt sensitive operations when cryptographic components are unavailable.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-AVAIL-017","requirement":"The boot manager shall enter recovery mode or reset on security violations and shall not bypass security controls on failure.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with recovery capability.","assessment":null},{"id":"RQ-AVAIL-018","requirement":"The boot manager shall indicate errors with sufficient detail to guide recovery actions.","applicability":{},"applicabilityText":"Applies to all boot managers with recovery capability.","assessment":null},{"id":"RQ-AVAIL-019","requirement":"The boot manager shall maintain recovery accessibility even with corrupted primary image and preserve recovery capability across updates.","applicability":{},"applicabilityText":"Applies to all boot managers with update and recovery capabilities.","assessment":null}]},{"clause":"5.9","title":"Impact Minimisation","overview":"This subclause addresses CRA requirements for impact minimisation on other systems. Boot managers shall limit resource consumption, release hardware properly, and prevent cascading failures to connected devices or networks.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-IMPACT-001","requirement":"The boot manager shall avoid broadcast storms and network loops during network operations.","applicability":{},"applicabilityText":"Applies to all boot managers with network boot.","assessment":null}]},{"clause":"5.10","title":"Attack Surface Minimisation","overview":"This subclause addresses CRA requirements for attack surface minimisation. Boot managers shall implement minimal functionality, eliminate debug interfaces, and restrict all non-essential capabilities in production builds.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-SURFACE-001","requirement":"The boot manager shall exclude non-essential code from production builds including test code, debug instrumentation, coverage tools, experimental features, and unsupported platform code.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-SURFACE-002","requirement":"The boot manager shall disable debug interfaces, diagnostic consoles, test modes, and verbose logging in production configuration.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-SURFACE-003","requirement":"The boot manager shall disable unused hardware interfaces, legacy protocols, and non-essential network services.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-SURFACE-004","requirement":"The boot manager shall not expose debug shells, diagnostic consoles, or interactive command interfaces in production configuration.","applicability":{},"applicabilityText":"Applies to all boot managers with debug interface.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-SURFACE-005","requirement":"The boot manager shall require authentication before activation of debug capabilities that cannot be disabled.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-SURFACE-006","requirement":"The boot manager shall validate all inputs with bounds checking and size limits, reject malformed or oversized data.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-SURFACE-007","requirement":"The boot manager shall perform verification checks using at least two independent mechanisms.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers.","assessment":null},{"id":"RQ-SURFACE-008","requirement":"The boot manager shall validate structure and format of boot images, certificates, configuration, and cryptographic data before processing.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-SURFACE-009","requirement":"The boot manager shall detect errors in critical operations and reject non-compliant inputs; transition to error handling on faults.","applicability":{},"applicabilityText":"Applies to all boot managers with network boot.","assessment":null},{"id":"RQ-SURFACE-010","requirement":"The boot manager shall protect configuration by detecting unauthorised modifications, using checksums/hashes, and limiting configurable options to essential parameters.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level MEDIUM. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}}]},{"clause":"5.11","title":"Logging and Monitoring","overview":"This subclause addresses CRA requirements for security monitoring. Boot managers shall provide visibility into boot processes through logs and attestation within pre-OS constraints of limited storage and no file systems.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-LOG-001","requirement":"The boot manager shall record measurements of boot components and security-critical configuration in tamper-resistant storage before execution or handoff.","applicability":{},"applicabilityText":"Applies to all boot managers with measured boot.","assessment":null},{"id":"RQ-LOG-002","requirement":"The boot manager shall protect measurement records from unauthorised modification or deletion using cryptographic mechanisms, hardware-protected storage, or tamper-evident recording.","applicability":{},"applicabilityText":"Applies to all boot managers with verified or measured boot.","assessment":null},{"id":"RQ-LOG-003","requirement":"The boot manager shall provide measurement records in a format supporting remote attestation by external parties, with freshness mechanisms to prevent replay of stale measurements, including component hashes, register indices, event types, and version information.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with measured boot.","assessment":null},{"id":"RQ-LOG-004","requirement":"The boot manager shall indicate security-relevant failures and state changes including verification failures, authentication failures, security policy violations, recovery mode activation, and execution of unsigned code.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":{"objective":"Verify secure configuration management: secure defaults, authentication controls, debug interface protection, and policy integrity.","preparation":"- Device in factory-default state or reset per manufacturer procedure\n- Manufacturer security documentation\n- Valid and invalid credential sets\n- Interface enumeration capability\n- Serial/debug console access where applicable","activities":"**6.2.5.1 Default state verification**\n\n**Objective**: Verify secure initial state without user configuration.\n\n**Activities (all tiers):**\n\n1. Review documentation for default security state\n2. Confirm no default passwords or undocumented access declared\n3. Verify secure defaults restorable\n\n**Verdict:**\n\n- PASS if secure defaults documented and restorable with no default credentials.\n- FAIL if default passwords present, undocumented access exists, or defaults not restorable.\n\n**6.2.5.2 Configuration authentication**\n\n**Applies**: Procedure 6.1.7.2 to configuration interface access.\n\n**Scope**: Boot security policy, boot order, security settings.\n\n**Verdict:**\n\n- PASS if configuration changes require authentication.\n- FAIL if unauthenticated policy modification possible, boot order changeable without authentication, or security settings modifiable anonymously.\n\n**6.2.5.3 Debug interface restriction**\n\n**Objective**: Verify debug interfaces secured in production.\n\n**Activities (Basic):**\n\n1. Review documentation for debug interface state\n2. Confirm debug disabled or authenticated in production\n\n**Activities (Elevated):**\n\n3. Attempt debug access; verify disabled or requires authentication\n4. Verify manufacturing test modes disabled\n\n**Activities (Advanced):**\n\n5. Verify debug cannot be re-enabled without authentication\n6. Verify debug authentication resists bypass\n\n**Verdict:**\n\n- PASS if debug interfaces disabled or authenticated in production.\n- FAIL if debug accessible without authentication, test modes active, or debug re-enableable without authorisation.\n\n**6.2.5.4 Policy integrity**\n\n**Applies**: Procedure 6.1.7.3 to security policy storage.\n\n**Scope**: Boot policies, security configuration, trust anchors.\n\n**Verdict:**\n\n- PASS if policy tampering detected and rejected.\n- FAIL if modified policy accepted, tampering undetected, or policy rollback possible without detection.\n\n**6.2.5.5 Credential protection**\n\n**Objective**: Verify password/credential storage security.\n\n**Activities (Elevated):**\n\n1. Review documentation for credential storage\n2. Verify passwords hashed, not stored plaintext\n3. Verify salt used in password hashing\n\n**Activities (Advanced):**\n\n4. Verify credential storage protected from extraction\n5. Verify secure credential comparison (timing-safe)\n\n**Verdict:**\n\n- PASS if credentials hashed with salt and protected from extraction.\n- FAIL if plaintext storage, missing salt, or credentials extractable.\n\n**6.2.5.6 Physical presence**\n\n**Objective**: Verify critical operations require physical presence.\n\n**Activities (Advanced):**\n\n1. Review documentation for physical presence requirements\n2. Attempt remote trust anchor modification; verify rejection\n3. Verify physical presence mechanism documented\n\n**Verdict:**\n\n- PASS if trust anchor changes require physical presence.\n- FAIL if remote trust anchor modification possible or physical presence bypassable.\n\n**6.2.5.7 Configuration logging**\n\n**Applies**: Procedure 6.1.7.1 to configuration events.\n\n**Scope**: Policy changes, authentication attempts, security state transitions.\n\n**Verdict**:\n\n- PASS if configuration changes logged with actor and outcome.\n- FAIL if changes unlogged, actor missing, or outcome not recorded.","verdict":"- **PASS (LOW)**: All applicable Basic-tier activities pass.\n- **PASS (MEDIUM)**: All applicable Basic and Elevated-tier activities pass.\n- **PASS (HIGH)**: All applicable Basic, Elevated, and Advanced-tier activities pass.\n- **FAIL**: Any required activity for the declared risk level fails.","evidence":"| Evidence | LOW | MEDIUM | HIGH |\n|----------|-----|--------|------|\n| Manufacturer documentation | X | X | X |\n| Configuration logs | X | X | X |\n| Debug interface test results | -- | X | X |\n| Credential storage analysis | -- | X | X |\n| Physical presence test results | -- | -- | X |","guidance":"NOTE (Vandorisk): EA-BM-CONFIG (clause 6.2) is a shared assessment profile: the draft assesses the requirements listed in its clause 6.2.1 reference table together, without per-requirement activities. The reference table assigns this requirement risk level LOW. Common assessment procedures (clause 6.1.7) apply where the activities reference them.\n\nApplicability of activities per tier and capability (clause 6.2.3):\n\n| Activity | Basic | Elevated | Advanced | Capability Condition |\n|----------|-------|----------|----------|---------------------|\n| 6.2.5.1 Default state | X | X | X | -- |\n| 6.2.5.2 Configuration authentication | X | X | X | Configuration |\n| 6.2.5.3 Debug interface restriction | X | X | X | -- |\n| 6.2.5.4 Policy integrity | -- | X | X | Configuration |\n| 6.2.5.5 Credential protection | -- | X | X | Password authentication |\n| 6.2.5.6 Physical presence | -- | -- | X | Configuration |\n| 6.2.5.7 Configuration logging | X | X | X | Configuration + logging |"}},{"id":"RQ-LOG-005","requirement":"The boot manager shall protect confidentiality of measurement records during transmission to external verifiers.","applicability":{},"applicabilityText":"Applies to all boot managers with measured boot.","assessment":null}]},{"clause":"5.12","title":"Vulnerability Management","overview":"This subclause addresses CRA requirements for vulnerability management. Boot managers shall support secure updates throughout product lifecycle, or clearly document limitations and compensating controls for non-updateable implementations.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[{"id":"RQ-VULN-001","requirement":"The boot manager shall provide version information accessible to operating system or management systems.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-VULN-002","requirement":"The boot manager shall implement update mechanisms enabling vulnerability remediation where update capability exists.","applicability":{},"applicabilityText":"Applies to all boot managers.","assessment":null},{"id":"RQ-VULN-003","requirement":"The boot manager shall implement status indicators for available updates where user interfaces exist.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with update and configuration capabilities.","assessment":null},{"id":"RQ-VULN-004","requirement":"The boot manager shall support update availability checks when network capable.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with update capability.","assessment":null},{"id":"RQ-VULN-005","requirement":"The boot manager shall implement at least two distinct security mechanisms (e.g., memory protection and input validation, or hardware isolation and cryptographic verification).","applicability":{},"applicabilityText":"Applies to all boot managers without update capability.","assessment":null},{"id":"RQ-VULN-006","requirement":"The boot manager shall enable security policy updates through configuration, allow disabling features to address vulnerabilities, and maintain configuration update capability throughout product lifetime.","applicability":{},"applicabilityText":"Applies to all boot managers with configuration capability.","assessment":null},{"id":"RQ-VULN-007","requirement":"The boot manager shall verify updates before committing, accept updates only from authenticated sources, and store update verification keys in hardware security component where available.","applicability":{},"applicabilityText":"Applies to all boot managers with update capability.","assessment":null},{"id":"RQ-VULN-008","requirement":"The boot manager shall execute update operations atomically, maintain backup of previous version, and automatically rollback on update failure.","applicability":{},"applicabilityText":"Applies to all boot managers with update capability.","assessment":null},{"id":"RQ-VULN-009","requirement":"The boot manager shall isolate update logic from normal boot path, preventing update failures from affecting other components.","applicability":{},"applicabilityText":"Applies to all boot managers with update capability.","assessment":null},{"id":"RQ-VULN-010","requirement":"The boot manager shall receive updates over authenticated and encrypted communication channel and detect tampering during update process.","applicability":{},"applicabilityText":"Applies to MEDIUM and HIGH risk boot managers with network updates.","assessment":null}]},{"clause":"5.13","title":"Security Testing and Review","overview":"Security testing requirements are addressed through conformity assessment procedures in clause 6 and documentation requirements in Annex C.","addressedBy":[],"otherRequirements":[],"mappingTable":{},"requirements":[]}],"rdps":{"applicability":"","families":[],"requirements":[]},"threats":[{"id":"T-INTEGRITY","title":"Boot integrity attacks","description":"Boot integrity attacks target the authenticity and trustworthiness of boot components, attempting to execute unauthorised code, weaken security policies, bypass verification mechanisms, or exploit parsing and input validation weaknesses."},{"id":"T-PERSIST","title":"Persistent firmware threats","description":"Persistent firmware threats establish malware or compromise that survives operating system reinstallation, disk formatting, and traditional security remediation."},{"id":"T-PHYS","title":"Physical attacks","description":"Physical attacks require direct hardware access to extract secrets, modify hardware, inject faults, or manipulate components. Physical security context determines attack feasibility more than boot manager capabilities."},{"id":"T-SUPPLY","title":"Supply chain attacks","description":"Supply chain attacks compromise boot managers during manufacturing, development, distribution, or through systemic trust failures. These threats affect all products regardless of capabilities, though update mechanisms expand the attack surface."},{"id":"T-NET","title":"Network-based attacks","description":"Network-based attacks exploit network connectivity during boot, update, or configuration processes, providing remote attack surface. These attacks occur before operating system security mechanisms are active."},{"id":"T-AVAIL","title":"Availability and resilience threats","description":"Availability and resilience threats prevent successful boot completion, cause denial of service, or undermine recovery mechanisms that ensure operational continuity."}],"draftGaps":["Clause 6 announces assessment profiles \"Clauses 6.2-6.7\" (clause 6.1.6) but this interim draft contains only one, EA-BM-CONFIG (clause 6.2). 78 of 98 requirements therefore have no assessment in the draft: RQ-SBD (4), RQ-DEFAULT (1), RQ-CONFID (9), RQ-INTEGRITY (21), RQ-MINIMAL (3), RQ-AVAIL (19), RQ-IMPACT (1), RQ-SURFACE (6), RQ-LOG (4), RQ-VULN (10).","EA-BM-CONFIG is a profile-level assessment shared by the 20 requirements in its clause 6.2.1 reference table; the draft does not break its activities down per requirement. Each covered requirement carries the full profile verbatim, with the requirement's table-assigned risk level noted in the assessment guidance.","Clause 6.1.6 (\"Assessment tier derivation\") carries an unresolved editor's note: \"#FIXME discuss approach\".","Requirement applicability is prose over risk level (LOW/MEDIUM/HIGH per clause 4.7.8) and product capabilities (clause 4.3.3), not a per-use-case table. The per-use-case applicability maps are therefore empty and every requirement is treated as applicable until the user applies the stated condition.","The risk-level determination machinery (risk factors in clause 4.7.8, capability and risk-factor tables in clauses 4.8.7-4.8.8) is not modelled by this pack: the use cases are informative deployment contexts and the pack cannot compute a product's risk level.","Clause 5.13 (Security Testing and Review) defines no requirements; it delegates to clause 6 and Annex C."]}