Part I
Product requirements
- 01Delivered with no known exploitable vulnerabilities
- 02Secure-by-default configuration, with the ability to reset
- 03Security updates available, and automatic where appropriate
- 04Protection against unauthorised access with strong authentication
- 05Confidentiality of stored, transmitted, and processed data
- 06Integrity protection for data, commands, and configuration
- 07Data minimisation limited to what the product actually needs
- 08Availability of essential functions and resilience to denial of service
- 09Minimised impact of the product or connected devices on the availability of services provided by other devices or networks
- 10Minimised attack surface, including exposed interfaces
- 11Mitigation of exploitation impact through hardening and segmentation
- 12Recording and monitoring of security-relevant activity
- 13Secure and complete deletion of data and settings on demand