Part I
Product requirements
- 01Delivered with no known exploitable vulnerabilities
- 02Secure-by-default configuration, with the ability to reset
- 03Security updates available, and automatic where appropriate
- 04Protection against unauthorised access with strong authentication
- 05Confidentiality of stored, transmitted, and processed data
- 06Integrity protection for data, commands, and configuration
- 07Data minimisation limited to what the product actually needs
- 08Availability of essential functions and resilience to denial of service
- 09Minimised attack surface, including exposed interfaces
- 10Mitigation of exploitation impact through hardening and segmentation
- 11Recording and monitoring of security-relevant activity
- 12Secure and complete deletion of data and settings on demand