{
    "Disclaimer": [
        "The information in this database is for general guidance and is not to be relied upon as professional advice.",
        "DSIT has tried to ensure that the information on this database is accurate and up to date. DSIT will not accept liability for any loss and/or damage or inconvenience arising as a consequence of any use of or the inability to use any information on this website. DSIT endeavours to provide a reliable service; DSIT does not guarantee that its service will be uninterrupted or error-free. DSIT shall not be responsible for claims brought by third parties arising from your use of this database.",
        "DSIT assumes no responsibility for the contents of linked websites. The inclusion of any link should not be taken as endorsement of any kind by DSIT of the linked website or any association with its operators. DSIT has no control over the availability of the linked pages."
    ],
    "Copyright": "The copyright of the original material remains that of the original authors and any usage of excerpts in the mapping is made under fair use. References to organisations do not imply endorsement by DSIT.",
    "Version": "3.0",
    "Data": {
        "GSMA": {
            "Mobile Device Certification Scheme": {
                "link": "https://www.gsma.com/solutions-and-impact/technologies/security/wp-content/uploads/2025/02/FS.56-v1.0.pdf",
                "requirements": [
                    {
                        "requirementID": "ALC_CMS.2.2E",
                        "requirementText": "The evaluator shall confirm that for external software components, the developer shall include the source and original maintainer of the component."
                    },
                    {
                        "requirementID": "ALC_FLR.3.5D",
                        "requirementText": "The developer shall provide a public vulnerability disclosure program to provide security bulletins about the flaws that have been remediated."
                    },
                    {
                        "requirementID": "ALC_FLR.3.6D",
                        "requirementText": "The developer shall establish procedures for ensuring that no known security vulnerabilities rated as High and Critical (e.g. as classified in public databases) are included in the TOE at public release."
                    },
                    {
                        "requirementID": "ALC_FLR.3.14C",
                        "requirementText": "The flaw remediation procedures documentation shall describe the process for publicly releasing security flaw remediation information, including the location(s) where this will be publicly available."
                    },
                    {
                        "requirementID": "ALC_FLR.3.15C",
                        "requirementText": "The flaw remediation procedures documentation shall describe the process for verifying known security flaws are not propagated into a new (not yet released) TOE."
                    }
                ]
            }
        },
        "NIAP": {
            "NIAP Profile Protection": {
                "link": "https://www.niap-ccevs.org/static_html/protection-profile/516/PP_APP_V2.0.htm",
                "requirements": [
                    {
                        "requirementID": "Basic Flaw Remediation\nALC_FLR.1.1D",
                        "requirementText": "The developer shall document and provide flaw remediation procedures addressed to TOE developers. "
                    },
                    {
                        "requirementID": "ALC_FLR.1.1C\n",
                        "requirementText": "The flaw remediation procedures documentation shall describe the procedures used to track all reported security flaws in each release of the TOE."
                    },
                    {
                        "requirementID": "ALC_FLR.1.2C",
                        "requirementText": "The flaw remediation procedures shall require that a description of the nature and effect of each security flaw be provided, as well as the status of finding a correction to that flaw."
                    },
                    {
                        "requirementID": "ALC_FLR.1.3C",
                        "requirementText": "The flaw remediation procedures shall require that corrective actions be identified for each of the security flaws. "
                    },
                    {
                        "requirementID": "ALC_FLR.1.4C",
                        "requirementText": "The flaw remediation procedures documentation shall describe the methods used to provide flaw information, corrections and guidance on corrective actions to TOE users."
                    },
                    {
                        "requirementID": "ALC_FLR.1.1E",
                        "requirementText": "The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence."
                    },
                    {
                        "requirementID": "ALC_FLR.2.1D",
                        "requirementText": "The developer shall document and provide flaw remediation procedures addressed to TOE developers."
                    },
                    {
                        "requirementID": "ALC_FLR.2.2D",
                        "requirementText": "The developer shall establish a procedure for accepting and acting upon all reports of security flaws and requests for corrections to those flaws."
                    },
                    {
                        "requirementID": "ALC_FLR.2.3D",
                        "requirementText": "The developer shall provide flaw remediation guidance addressed to TOE users."
                    },
                    {
                        "requirementID": "ALC_FLR.2.1C",
                        "requirementText": "The flaw remediation procedures documentation shall describe the procedures used to track all reported security flaws in each release of the TOE."
                    },
                    {
                        "requirementID": "ALC_FLR.2.2C",
                        "requirementText": "The flaw remediation procedures shall require that a description of the nature and effect of each security flaw be provided, as well as the status of finding a correction to that flaw."
                    },
                    {
                        "requirementID": "ALC_FLR.2.3C",
                        "requirementText": "The flaw remediation procedures shall require that corrective actions be identified for each of the security flaws."
                    },
                    {
                        "requirementID": "ALC_FLR.2.4C",
                        "requirementText": "The flaw remediation procedures documentation shall describe the methods used to provide flaw information, corrections and guidance on corrective actions to TOE users."
                    },
                    {
                        "requirementID": "ALC_FLR.2.5C",
                        "requirementText": "The flaw remediation procedures shall describe a means by which the developer receives from TOE users reports and enquiries of suspected security flaws in the TOE."
                    },
                    {
                        "requirementID": "ALC_FLR.2.6C",
                        "requirementText": "The procedures for processing reported security flaws shall ensure that any reported flaws are remediated and the remediation procedures issued to TOE users."
                    },
                    {
                        "requirementID": "ALC_FLR.2.7C",
                        "requirementText": "The procedures for processing reported security flaws shall provide safeguards that any corrections to these security flaws do not introduce any new flaws."
                    },
                    {
                        "requirementID": "ALC_FLR.2.8C",
                        "requirementText": "The flaw remediation guidance shall describe a means by which TOE users report to the developer any suspected security flaws in the TOE."
                    },
                    {
                        "requirementID": "ALC_FLR.2.1E",
                        "requirementText": "The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence."
                    },
                    {
                        "requirementID": "ALC_FLR.3.1D",
                        "requirementText": "The developer shall document and provide flaw remediation procedures addressed to TOE developers."
                    },
                    {
                        "requirementID": "ALC_FLR.3.2D",
                        "requirementText": "The developer shall establish a procedure for accepting and acting upon all reports of security flaws and requests for corrections to those flaws."
                    },
                    {
                        "requirementID": "ALC_FLR.3.3D",
                        "requirementText": "The developer shall provide flaw remediation guidance addressed to TOE users."
                    },
                    {
                        "requirementID": "ALC_FLR.3.1C",
                        "requirementText": "The flaw remediation procedures documentation shall describe the procedures used to track all reported security flaws in each release of the TOE."
                    },
                    {
                        "requirementID": "ALC_FLR.3.2C",
                        "requirementText": "The flaw remediation procedures shall require that a description of the nature and effect of each security flaw be provided, as well as the status of finding a correction to that flaw."
                    },
                    {
                        "requirementID": "ALC_FLR.3.3C",
                        "requirementText": "The flaw remediation procedures shall require that corrective actions be identified for each of the security flaws."
                    },
                    {
                        "requirementID": "ALC_FLR.3.4C",
                        "requirementText": "The flaw remediation procedures documentation shall describe the methods used to provide flaw information, corrections and guidance on corrective actions to TOE users."
                    },
                    {
                        "requirementID": "ALC_FLR.3.5C",
                        "requirementText": "The flaw remediation procedures shall describe a means by which the developer receives from TOE users reports and enquiries of suspected security flaws in the TOE."
                    },
                    {
                        "requirementID": "ALC_FLR.3.6C",
                        "requirementText": "The flaw remediation procedures shall include a procedure requiring timely response and the automatic distribution of security flaw reports and the associated corrections to registered users who might be affected by the security flaw."
                    },
                    {
                        "requirementID": "ALC_FLR.3.7C",
                        "requirementText": "The procedures for processing reported security flaws shall ensure that any reported flaws are remediated and the remediation procedures issued to TOE users."
                    },
                    {
                        "requirementID": "ALC_FLR.3.8C",
                        "requirementText": "The procedures for processing reported security flaws shall provide safeguards that any corrections to these security flaws do not introduce any new flaws."
                    },
                    {
                        "requirementID": "ALC_FLR.3.9C",
                        "requirementText": "The flaw remediation guidance shall describe a means by which TOE users report to the developer any suspected security flaws in the TOE."
                    },
                    {
                        "requirementID": "ALC_FLR.3.10C",
                        "requirementText": "The flaw remediation guidance shall describe a means by which TOE users may register with the developer, to be eligible to receive security flaw reports and corrections."
                    },
                    {
                        "requirementID": "ALC_FLR.3.11C",
                        "requirementText": "The flaw remediation guidance shall identify the specific points of contact for all reports and enquiries about security issues involving the TOE."
                    },
                    {
                        "requirementID": "ALC_FLR.3.1E",
                        "requirementText": "The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence."
                    }
                ]
            }
        },
        "ETSI": {
            "EN 303 645 - Cyber Security for Consumer Internet of Things: Baseline Requirements": {
                "link": "https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.03_60/en_303645v030103p.pdf",
                "requirements": [
                    {
                        "requirementID": "Principle 5.2-1",
                        "requirementText": "The manufacturer shall make a vulnerability disclosure policy publicly available. This policy shall include, at a minimum:\n• contact information for the reporting of issues; and \n• timelines for initial acknowledgement of receipt of a vulnerability report; and \n• timelines for when the person who reported the issue will receive status updates until the resolution of the reported issues.\n\nNOTE 2: Different notations are possible to describe time values in the timetable (e.g. \"7 days\", \"quickly\", etc.). ETSI TR 103 838 [i.30] contains an example for a vulnerability disclosure policy including timelines for initial acknowledgement of receipt and a proposal for information on timelines for status updates until the resolution of the reported issues. The time needed to find a solution can vary depending e.g. on the criticality of the disclosed vulnerability.\n\nA vulnerability disclosure policy clearly specifies the process through which security researchers and others are able to report issues. Such policy can be updated as necessary to further ensure transparency and clarity in the dealings of the manufacturer with security researchers, and vice versa.\n\nCoordinated Vulnerability Disclosure (CVD) is a set of processes for dealing with disclosures about potential security vulnerabilities and to support the remediation of these vulnerabilities. CVD is standardized by the International Organization for Standardization (ISO) in the ISO/IEC 29147 [i.4] on vulnerability disclosure. Moreover, a guide to CVD is given in ETSI TR 103 838 [i.30]. CVD has been proven to be successful in some large software companies around the world. Multi-Party Coordinated Vulnerability Disclosure (MPCVD) refers to the application of CVD in a multi-stakeholder scenario, for example when products from multiple manufacturers are affected by the same vulnerability. Manufacturers can refer to the guidelines from ISO/IEC TR 5895 [i.33] and FIRST [i.32] to adapt their CVD processes accordingly.\n\nIn the IoT industry, CVD is currently not well-established [i.16] as some companies are reticent about dealing with security researchers. Here, CVD provides companies a framework to manage this process. This gives security researchers an avenue to inform companies of security issues, puts companies ahead of the threat of malicious exploitation and gives companies an opportunity to respond to and resolve vulnerabilities in advance of a public disclosure."
                    },
                    {
                        "requirementID": "Principle 5.2-2",
                        "requirementText": "Disclosed vulnerabilities should be acted on in a timely manner.\n\nA \"timely manner\" for acting on vulnerabilities varies considerably and is incident-specific; however, conventionally, the vulnerability management process is following a properly documented process including clear responsibilities and completed within 90 days for a software solution, including availability of patches and notification of the issue. A hardware fix can take considerably longer to address than a software fix. Additionally, a fix that has to be deployed to devices can take time to roll out compared with a server software fix."
                    },
                    {
                        "requirementID": "Principle 5.2-3",
                        "requirementText": "Manufacturers should continually monitor for, identify and rectify security vulnerabilities within consumer IoT products they sell, produce, have produced and associated services they operate during the defined support period.\n\nNOTE 3: Manufacturers are expected to exercise due care for all software and hardware components used in the product, this includes due care related to the selected third parties that provide associated services to support the functions of the product.\n\nSoftware solutions often contain open source and third party software components. Creating and maintaining list of all software components and their sub-components is a pre-requisite to be able to monitor for product vulnerabilities. Various tools exist to scan source code and binaries and build a so-called Software Bill Of Materials (SBOM), which identifies third party components and the versions used in the product. This information is then used to monitor for the associated security and licensing risks of each identified software component.\n\nVulnerabilities are expected to be reported directly to the affected stakeholders in the first instance. If that is not possible, vulnerabilities can be reported to national authorities. Manufacturers are also encouraged to share information with competent industry bodies, such as the GSMA [i.21] and the IoT Security Foundation. Guidance on Coordinated Vulnerability Disclosure is available from the IoT Security Foundation [i.22] which references ISO/IEC 29147 [i.4].\n\nThe management of vulnerabilities is expected to be performed for devices within their defined support period. However, manufacturers can continue this outside that period and release security updates to rectify vulnerabilities. "
                    }
                ]
            },
            "EN 319 401 - General Policy Requirements for Trust Service Providers": {
                "link": "https://www.etsi.org/deliver/etsi_en/319400_319499/319401/03.02.00_20/en_319401v030200a.pdf",
                "requirements": [
                    {
                        "requirementID": "REQ-7.9.2-10",
                        "requirementText": "For any vulnerability, given the potential impact, the TSP shall [CHOICE]:\n- create and implement a plan to mitigate the vulnerability; or\n- document the factual basis for the TSP's determination that the vulnerability does not require remediation.\n\nEXAMPLE 2: The TSP can determine that the vulnerability does not require remediation when the cost of the potential impact does not warrant the cost of mitigation."
                    },
                    {
                        "requirementID": "REQ-7.9.2-11",
                        "requirementText": "Incident reporting and response procedures shall be employed in such a way that damage from security incidents and malfunctions are minimized."
                    },
                    {
                        "requirementID": "REQ-7.9.2-12",
                        "requirementText": "The TSP shall appoint trusted role personnel to follow up on alerts of potentially critical security events and ensure that relevant incidents are reported in line with the TSP's procedures."
                    },
                    {
                        "requirementID": "REQ-7.9.2-15",
                        "requirementText": "The TSP shall respond to incidents in accordance with documented procedures and in a timely manner."
                    },
                    {
                        "requirementID": "REQ-7.9.2-16",
                        "requirementText": "The incident response procedures shall include the following stages:\na) incident containment, to prevent the consequences of the incident from spreading;\nb) eradication, to prevent the incident from continuing or reappearing;\nc) recovery from the incident, where necessary."
                    },
                    {
                        "requirementID": "REQ-7.9.2-17",
                        "requirementText": "The TSP shall establish communication plans and procedures:\na) with the Computer Security Incident Response Teams (CSIRTs) or, where applicable, the competent authorities, related to incident notification;\nb) for communication among staff members of the TSP, and for communication with relevant stakeholders external to the TSP."
                    },
                    {
                        "requirementID": "REQ-7.9.2-18",
                        "requirementText": "The TSP shall log incident response activities in accordance with the monitoring and logging procedures, and record evidence."
                    },
                    {
                        "requirementID": "REQ-7.9.2-19",
                        "requirementText": "The TSP shall test at planned intervals their incident response procedures."
                    },
                    {
                        "requirementID": "REQ-7.9.3-01",
                        "requirementText": "The TSP shall establish procedures to notify the appropriate parties in line with the applicable regulatory rules of any breach of security or loss of integrity that has a significant impact on the trust service provided and on the personal data maintained therein within 24 hours of the breach being identified."
                    },
                    {
                        "requirementID": "REQ-7.9.3-05",
                        "requirementText": "The TSP shall put in place a simple mechanism allowing their employees, suppliers, and customers to report suspicious events."
                    },
                    {
                        "requirementID": "REQ-7.9.4-01",
                        "requirementText": "The TSP shall analyse the reported events and assess their severity."
                    },
                    {
                        "requirementID": "REQ-7.9.4-03",
                        "requirementText": "The TSP shall assess suspicious events to determine whether they constitute incidents and, if so, determine their nature and severity."
                    },
                    {
                        "requirementID": "REQ-7.9.5-02",
                        "requirementText": "The TSP shall evaluate the TSP's exposure to such vulnerabilities and take appropriate measures."
                    },
                    {
                        "requirementID": "REQ-7.9.5-03",
                        "requirementText": "The TSP shall identify the root cause of an incident and shall conduct a post-incident review possibly resulting in measures mitigating the risk of the recurrence of similar incidents."
                    },
                    {
                        "requirementID": "REQ-7.9.5-04",
                        "requirementText": "The TSP shall ensure that each past incident led to a post-incident review."
                    },
                    {
                        "requirementID": "REQ-7.9.5-05",
                        "requirementText": "Where appropriate, the TSP may carry out post-incident reviews after recovery from incidents."
                    },
                    {
                        "requirementID": "REQ-7.9.5-06",
                        "requirementText": "The post-incident reviews shall, if carried out, identify, where possible, the root cause of the incident and result in documented lessons learned to reduce the occurrence and consequences of future incidents."
                    },
                    {
                        "requirementID": "REQ-7.9.5-07",
                        "requirementText": "The TSP shall ensure that post-incident reviews contribute to improving their approach to network and information security, to risk treatment measures, and to incident handling, detection and response procedures."
                    },
                    {
                        "requirementID": "REQ-7.9.5-08",
                        "requirementText": "The TSP shall review at planned intervals if incidents led to post-incident reviews."
                    },
                    {
                        "requirementID": "REQ-7.10-01",
                        "requirementText": "The TSP shall record and keep accessible for an appropriate period of time, including after the activities of the TSP have ceased, all relevant information concerning data issued and received by the TSP, in particular, for the purpose of providing evidence in legal proceedings and for the purpose of ensuring continuity of the service."
                    }
                ]
            }
        }
    }
}