5.6-2: R In the initialized state, the network interfaces of the device shall minimize the unauthenticated disclosure of security-relevant information. 5.6-3: R Device hardware should not unnecessarily expose physical interfaces to attack. 5.6-4: RC Where a debug interface is (13) physically accessible, it shall be disabled in software. 5.6-5: R The manufacturer should only enable software services that are used or required for the intended use or operation of the device. 5.6-6: R Code should be minimized to the functionality necessary for the service/device to operate. R R M R R R RC (13) RC (13) MC (13) R R R R R R firewall rules should also be provided. Supporting evidence shall describe the measures taken to ensure that securityrelevant information is not exposed via the network interfaces of the device. Supporting evidence shall list all physical interfaces available on the device and describe any measures (if necessary) taken to secure physical interface(s) to fulfil this provision. Supporting evidence shall list all available hardware debug interfaces available and describe the steps taken in ensuring that they are disabled. Supporting evidence shall describe the software services available on the device and their status (enabled/disabled), along with a description of the rationale behind enabling and disabling each of these services. Supporting evidence shall list all software code and libraries available on the device and describe what has been done to minimise the existence of unused code. CLS Publication #2 | Page 36 of 49

Select target paragraph3