接下來我挑選 EN 304 627 這篇來說明,EN 304 627 是關於路由器相關的規範,這也是我為什麼選這篇,路由器算是常見的物聯網設備之一,相對來說好取得。
如何閱讀 EN 304 627:從產品判斷到實際測試
先判斷產品 → 建立 Product Context → 判斷適用要求 → 找 Technical Requirement → 找 Assessment Criteria → 建立 Test Case → 執行測試 → 判定結果
一、先判斷產品是不是 EN 304 627 的對象
EN 304 627 的範圍是:
- Router
- Modem intended for connection to the internet
- Switch
而且標準本身的 Product Context 還會進一步區分不同產品功能、部署環境與 Use Case。
所以拿到產品後,第一件事情不是掃 Port。
而是問:
「這台產品到底是不是 EN 304 627 要處理的產品?」
二、閱讀 Chapter 4 Product Context
Chapter 4 不是主要拿來做資安測試,而是用來了解: 「這個產品是什麼、有哪些功能、在哪裡使用?」
EN 304 627 的 Product Context 包含:
- Product Functions
- Product Architecture
- Product Assets
- Operational Environment
- Users
- Use Cases
例如 Router 可以確認:
- WAN
- LAN
- Wi-Fi
- Routing
- Firewall
- DHCP
- DNS
- Web Management
- Remote Management
三、建立產品功能清單
例如今天拿到一台 Wi-Fi Router,先把它有的功能列出來,這個清單非常重要。
因為後面要用它判斷, 哪些 Requirement 適用?
四、判斷 Applicability
接下來閱讀 Chapter 5 的 Applicability。
不要看到 Requirement 就全部測,產品有的功能再進行測試,沒有就不適用處理。

五、閱讀 Chapter 5
目前 EN 304 627 Chapter 5 的主要測試要求包括:
- [KEV-1] No Known Exploitable Vulnerabilities
- [DEFAULT-1] Secure by Default Configuration
- [RESET-1] Factory Reset
- [UPDATE-1] Update Mechanisms
- [AUTH-1] Authentication
- [AUTH-2] Authorisation
- [AUTH-3] Authenticated Session Lifecycle
- [AUTH-4] Protocol Access Control
- [DATA-1] Confidentiality Protection
- [AVAIL-1] Availability and Resilience
- [INTEGRITY-1] System Integrity and Boot Process
- [PACKET-1] Default Packet Disposition
- [EXPOSURE-1] Interface and Service Exposure Minimisation
- [LOG-1] Monitoring and Logging
- [TRANSFER-1] Secure Data Export and Transfer
這些項目在 Chapter 5 與 Chapter 6 是一一對應的。