commoncriteria / sdn-controller

Protection Profile for Software Defined Networking Controllers
The Unlicense
3 stars 0 forks source link

ESR; Resources to be protected #11

Open heimannrj opened 7 months ago

heimannrj commented 7 months ago

Is this section too specific and at risk of being too narrowly interpreted in the future? Some of the items listed appear to be examples of higher level concepts. Consider consolidating the current list into something higher level that can encompass new technologies and considerations over the long term. From this:

To this:

hubertdcruze commented 7 months ago

Thank you for your suggestions. It makes sense. Here are some of my thoughts as well. The key resources associated with SDN controllers that need to be protected:

  1. Control plane communications
  2. Network configuration data
  3. Authentication credentials
  4. Software and firmware
  5. Data stored locally and in transit
  6. APIs and management interfaces
  7. Cryptographic keys and certificates
  8. Audit logs and monitoring data
  9. Resource allocation information