5.5-4:
Access
to
device
functionality via a network
interface in the initialized
state should only be
possible
after
authentication
on
that
interface.
5.5-5:
Device functionality that
allows
security-relevant
changes in configuration
via a network interface shall
only be accessible after
authentication.
The
exception is for network
service protocols that are
relied upon by the device
and
where
the
manufacturer
cannot
guarantee
what
configuration
will
be
required for the device to
operate.
R
R
R
R
R
R
R
M
used could be updated with a software
update).
Supporting evidence shall list all network
interfaces on the device and the
authentication mechanisms available on
all of the network interfaces. In addition,
if certain device functionalities are
available prior to authentication, a
description of the purpose for allowing
those functionalities shall be provided.
Supporting evidence shall describe that
authentication is required prior to making
security-relevant changes.
Example scenarios:
•
•
•
Administrator's authentication is
required prior to making changes
in the device's web configuration
portal.
Administrator's authentication is
required prior to configuring
security-relevant changes to the
device using the companion
mobile application.
Authentication should also be
required
for
any
other
interfaces/methods that facilitates
making
security-relevant
changes.
CLS Publication #2 | Page 34 of 49