nmfta-repo / nmfta-telematics_security_requirements

Cybersecurity requirements for telematics systems developed in collaboration with motor freight carriers, telematics service providers and cybersecurity experts.
Other
4 stars 3 forks source link

add new TSRM requirements based unmatched UL 1376 requirements #31

Closed BenGardiner closed 2 years ago

BenGardiner commented 3 years ago

[these actions were review and approved by the RFCTL working group April 28th 2021]

There are a few UL requirements that the TSRM doesn't have equivalents of. We will add new requirements to the TSRM for all all of the following:

UL 1376 2.8 Brute force protection: Implement protection against brute force attacks

UL 1376 3.2 Systems configured to secure defaults: Systems must be configured to secure defaults

UL 1376 4.3 Manual back-up / override for safety critical operations: Manual backup/override must be provided for safety related services

UL 1376 4.5 Sensitive services implement session management: System management services accessible over wireless and IP interfaces must implement session management to limit multiple sessions, and ensure on-going authentication

UL 1376 1.5 Hardware root of trust: Device implements a hardware based root of trust for updates and boot authentication

UL 1376 2.6 Industry best practice key management: Cryptographic keys must be managed to industry best practice

NB: when the new requirements are added with obvious outwards xref to the UL 1376 requirements we need to search for and add references to anything matching in the existing public reference documents.