In addition to memory safety, compiled software is a potential target based on platform and language. Products hardened against these known attack vectors reduce risk to end users.
1.**REQ-SSD-06 (MI-SCFS)-1** Products shall incorporate built-in exploit mitigation mechanisms appropriate to the target platform and language (e.g., Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP/NX), or Stack Canaries), and
2.**REQ-SSD-06 (MI-SCFS)-2** any exceptions to these mitigations shall be documented as to how each exception does not create an unacceptable risk.
#### 5.2.6.2 Applicability
This requirement applies to products that are implemented in a compiled programming language **and** fall within the following use cases:
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-7: required
### 5.2.7 REQ-SSD-07 Applicability of Annex R
##### 5.2.7.1 Requirement
@@ -121,7 +98,6 @@ This requirement does not apply to UC-6 because by definition that use case does