iT邦幫忙

2026 iThome 鐵人賽

DAY 25
0

接下來我挑選 EN 304 627 這篇來說明,EN 304 627 是關於路由器相關的規範,這也是我為什麼選這篇,路由器算是常見的物聯網設備之一,相對來說好取得。

如何閱讀 EN 304 627:從產品判斷到實際測試

先判斷產品 → 建立 Product Context → 判斷適用要求 → 找 Technical Requirement → 找 Assessment Criteria → 建立 Test Case → 執行測試 → 判定結果

一、先判斷產品是不是 EN 304 627 的對象

EN 304 627 的範圍是:

  • Router
  • Modem intended for connection to the internet
  • Switch

而且標準本身的 Product Context 還會進一步區分不同產品功能、部署環境與 Use Case。

所以拿到產品後,第一件事情不是掃 Port。

而是問:

「這台產品到底是不是 EN 304 627 要處理的產品?」

二、閱讀 Chapter 4 Product Context

Chapter 4 不是主要拿來做資安測試,而是用來了解: 「這個產品是什麼、有哪些功能、在哪裡使用?」

EN 304 627 的 Product Context 包含:

  • Product Functions
  • Product Architecture
  • Product Assets
  • Operational Environment
  • Users
  • Use Cases

例如 Router 可以確認:

  • WAN
  • LAN
  • Wi-Fi
  • Routing
  • Firewall
  • DHCP
  • DNS
  • Web Management
  • Remote Management

三、建立產品功能清單

例如今天拿到一台 Wi-Fi Router,先把它有的功能列出來,這個清單非常重要。

因為後面要用它判斷, 哪些 Requirement 適用?

四、判斷 Applicability

接下來閱讀 Chapter 5 的 Applicability。

不要看到 Requirement 就全部測,產品有的功能再進行測試,沒有就不適用處理。

https://ithelp.ithome.com.tw/upload/images/20261008/20184112Aak6BrH1s0.png

五、閱讀 Chapter 5

目前 EN 304 627 Chapter 5 的主要測試要求包括:

  1. [KEV-1] No Known Exploitable Vulnerabilities
  2. [DEFAULT-1] Secure by Default Configuration
  3. [RESET-1] Factory Reset
  4. [UPDATE-1] Update Mechanisms
  5. [AUTH-1] Authentication
  6. [AUTH-2] Authorisation
  7. [AUTH-3] Authenticated Session Lifecycle
  8. [AUTH-4] Protocol Access Control
  9. [DATA-1] Confidentiality Protection
  10. [AVAIL-1] Availability and Resilience
  11. [INTEGRITY-1] System Integrity and Boot Process
  12. [PACKET-1] Default Packet Disposition
  13. [EXPOSURE-1] Interface and Service Exposure Minimisation
  14. [LOG-1] Monitoring and Logging
  15. [TRANSFER-1] Secure Data Export and Transfer

這些項目在 Chapter 5 與 Chapter 6 是一一對應的。


上一篇
Day 24|CRA 相關水平與垂直法規
系列文
30天探索CRA奇妙之旅! 共 25 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言