Clause 5.5: Remove redundant and not allowed secure update documentation reqs
We can't require documentation and these are redundant with update via
operational environment (coming soon as an expansion of the
administrator options).
@@ -217,23 +217,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
#### 5.5.1.2 Guidance for updates before or during first use (MI-KEVD, MI-KEVA, MI-KEVE)
Recognizing that there may be vulnerabilities discovered between the time that a product is placed on the market and the time of that product's first use, and that the product should be free from known exploitable vulnerabilities both when first made available and when first used by a consumer, the product shall be able to be updated at the time of first use to address known exploitable vulnerabilities which were discovered after the product's placement on the market and before first use.
### 5.5.2 REQ-SU-02 (MI-KEVD) Documentation for secure update before or during first use
#### 5.5.2.1 Requirement
The product shall be accompanied by documentation describing how the product can be securely updated, including how to update the product prior to, or as part of, first use.
#### 5.5.2.2 Applicability
* UC-1: REQ-SU-02 (MI-KEVD) or REQ-SU-03 (MI-KEVA) apply
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: not required
* UC-7: required
Recognizing that there may be vulnerabilities discovered between the time that a product is placed on the market and the time of that product's first use, and that the product should be free from known exploitable vulnerabilities both when first made available and when first used by a consumer, the product should be able to be updated at the time of first use to address known exploitable vulnerabilities which were discovered after the product's placement on the market and before first use.
### 5.5.3 REQ-SU-03 (MI-KEVA) Automatic secure update before or during first use
@@ -316,22 +300,6 @@ Of those products, use-case applicability follows:
* UC-6: REQ-SU-06 (MI-SUAP) or REQ-SU-09 (MI-SUAO) apply
* UC-7: REQ-SU-06 (MI-SUAP) or REQ-SU-09 (MI-SUAO) apply
### 5.5.7 REQ-SU-07 (MI-SUDC) Documentation of secure update
#### 5.5.7.1 Requirement
The product shall be accompanied by documentation of the secure update methods for any software in the product.
#### 5.5.7.2 Applicability
* UC-1: not required
* UC-2: not required
* UC-3: not required
* UC-4: not required
* UC-5: not required
* UC-6: required
* UC-7: not required
### 5.5.8 REQ-SU-08 (MI-SUOE) Secure update provided by operational environment