Skip to main content
Tagasi
UUS

prEN 304 620 V1.0.0

Küberturvalisus (CYBER); CRA; Küberturvalisuse nõuded virtuaalsetele privaatvõrkudele (VPN)

Üldinfo

Kavand
Alusdokumendid
Draft ETSI EN 304 620 V1.0.0
Tegevusala (ICS grupid)
35.030 Infoturve
Direktiivid või määrused
puuduvad
Standardi kavandiga saab tutvuda kommenteerimisportaalis🡭.

Standardi ajalugu

Staatus
Kuupäev
Tüüp
Nimetus
The present document specifies technical requirements and corresponding assessment criteria for Virtual Private Networks related to cybersecurity. The products with digital elements in scope, thereafter "VPNs":
• are specified within the "technical description" of the "category of product" number "5" by the Commission Implementing Regulation (EU) 2025/2392 as: "Products with digital elements that establish an encrypted logical tunnel that is constructed from the system resources of a physical or virtual network".
• are only covered within the product context described in clause 4 and the text of this clause.
In particular, the present document specifies technical characteristics and methods of assessment for:
1) Software that operates as a VPN client or endpoint
2) Software that operates as a node within a mesh VPN network
3) Software that operates as a VPN server
4) Remote data processing, specifically VPN server software performing the logical server role, and associated software used for such VPN products
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 Annex I Part I under the conditions identified in Annex A.
VPN hardware or appliances, and control mechanisms for mesh VPNs are excluded from the present document. VPNs intended for use in the industrial Operational Technology (OT) domain are excluded from the scope of the present document, see prEN 50770 series.

Nõutud väljad on tähistatud *

*
*
*
Standardi monitooring