days on Freeform Penetration Testing. The objective of this freeform testing
is to serve as a feedback loop for the continuous refinement of the
minimum test specification so to align with the current threat landscape.
6.3.4 The developer shall facilitate the testing by the testing laboratory. For
example, by providing sufficient units of the devices to the testing
laboratory and responding to queries. The developer shall note that certain
tests might render the device to be unusable (e.g. physically damaged).
Device setup and verification of guidance documents
6.3.5 The objective of analysing the guidance document provided alongside the
DUT is to ensure that the user guidance does not mislead the user into
installing or operating the DUT in an insecure manner, and to minimise the
risk of human or other errors in operation that may affect the security of the
DUT.
6.3.6 The guidance document (i.e. user manual, installation guide, operation
guide, etc.) shall consist of clear steps that guides the end-user to install
and operate the DUT in a secure manner. The guidance document shall be
written in a manner that is easily understood by the typical user of the DUT.
As an example, for a smart home appliance, it can be assumed that the
typical user has little to no knowledge of cybersecurity. If the DUT functions
are configurable, the guidance document shall indicate secure values as
appropriate. The guidance document shall also describe possible modes
of operation of the DUT, their consequences and procedures for returning
the DUT back into a secure configuration.
6.3.7 The testing laboratory shall examine the guidance document(s) provided
to ensure that the guidance document provided meets the requirements
stated above.
ESTI Conformance Verification
6.3.8 As part of the application, the developer is required to declare against the
provisions specified in the checklist and provide evidence and descriptions
of how these requirements have been implemented by the device.
6.3.9 The testing laboratory examines that these security measures are indeed
being implemented and that such implementation are appropriate to fulfil
to the requirements.
Scheme-mandated Minimum Test Specifications
6.3.10 In order to ensure consistent penetration testing of connected products
across different testing laboratories, minimum test specifications for the
different categories of connected products are defined.
6.3.11 The testing laboratory shall ensure that the test objectives in the test
specifications are achieved prior to the conduct of independent
vulnerability analysis and penetration testing.
CLS Publication #2 | Page 16 of 49