Control Unmanaged

URI: Unmanaged

Package: Network

< prev | next >

Description: This control indicates that the management of a device is considered out of scope. It is used to tell SSM that where no manager is specified, that was deliberate and is not an oversight. Note that this only addresses the modelling error threat used to detect a possible oversight. It does not mean other threats that could be managed by a system manager are also ignored.

Host

A device that can store, process, transmit or receive data.

CSG-IgnoreManagementOfHost

Signifies that the management of device Host is omitted because it is out of scope, e.g. because its management does not form part of the system. Note that this means modelling error threats to detect unmanaged devices will be ignored, but threats that could be addressed by a system manager will still apply to the unmanaged devices.