Commit 04ad9db3 authored by Aki Braun's avatar Aki Braun
Browse files

Adding LOGG-4 & LOGG-5 to security analysis

parent e9ba7495
Loading
Loading
Loading
Loading
+5 −5
Original line number Diff line number Diff line
@@ -1037,7 +1037,7 @@ Mitigations for Impact:

### C.4.15 TH-META: Compromise of Personal Data due to metadata and traffic analysis

Attacker may use user metadata such as IP addresses and traffic analysis to compromise personally identifiable information.
Attacker may use user metadata such as IP addresses and traffic analysis to compromise Personal Data.

**Table C.4.15-1: Compromise of Personal Data due to metadata and traffic analysis**

@@ -1062,7 +1062,7 @@ Mitigations for Likelihood:

Mitigations for Impact:

* Medium to Low: TODO - transfer risk to user
* Medium to Low: LOGG-4, LOGG-5
* High to Low: TODO - transfer risk to user

### C.4.16 TH-RCOM: RDPS compromise and isolation
@@ -1094,7 +1094,7 @@ Mitigations for Likelihood:

Mitigations for Impact:

* Medium to Low: TODO
* Medium to Low: LOGG-4, LOGG-5
* High to Low: TODO

### C.4.17 TH-USED: Access to data via access to used product
@@ -1131,7 +1131,7 @@ Mitigations for Impact:

### C.4.18 TH-CPER: Compromise of Personal Data stored or transmitted by the product

Attacker may get unauthorised access to personally identifiable information stored or transmitted by the product.
Attacker may get unauthorised access to Personal Data stored or transmitted by the product.

**Table C.4.18-1: Compromise of Personal Data stored or transmitted by the product**

@@ -1154,7 +1154,7 @@ All mitigations from TH-UEAC, TH-MITM, TH-LEAK, TH-PLNS, TH-PLNM, TH-UNAA, TH-CO
Mitigations for Impact:

* Medium to Low: NPER-1
* High to Low: NPER-1, NPER-2, NPER-3, NPER-4
* High to Low: NPER-1, NPER-2, NPER-3, NPER-4, LOGG-4, LOGG-5

## C.5 Mapping of use cases to risk factors and security profiles

+4 −0
Original line number Diff line number Diff line
@@ -1151,6 +1151,8 @@ This clause lists all the mitigations necessary to meet requirements for each se
  1. KEVD
  1. LMEM
  1. LOGG-1
  1. LOGG-4
  1. LOGG-5
  1. NPER-1
  1. ROUT-1
  1. ROUT-2
@@ -1205,6 +1207,8 @@ This clause lists all the mitigations necessary to meet requirements for each se
  1. LMEM
  1. LOGG-1
  1. LOGG-2
  1. LOGG-4
  1. LOGG-5
  1. NPER-1
  1. NPER-2
  1. NPER-3