**Draft ETSI EN 304 620 v0.0.15 Part 1 (2025-12)**
ETSI **Draft EN 304 620 v0.0.15 Part 1 (2025-12)**

@@ -628,8 +628,6 @@ Rationale: The greater the information saved, the higher the odds that an attack
***[RDS-L-1]** Production instances of VPN infrastructure remotely save only minimal information necessary for security purposes, such as configuration changes
***[RDS-L-2]** Production instances of VPN infrastructure log sensitive information about the user and/or user behavior
> TODO-HAS: rename LDS/RDS (was LLG/RLG)
> TODO-HAS: add data leak threats
## C.3 Assumptions
@@ -670,8 +668,8 @@ For each threat, both likelihood and impact must be Low before the risk is consi
The risk factors by type are:
* Likelihood: CFG, AUT, ADM, LLG
* Impact: DAT, FUN, RLG, RDP
* Likelihood: CFG, AUT, ADM, LDS
* Impact: DAT, FUN, RDS, RDP
The mitigations that reduce risk by type are:
@@ -695,7 +693,7 @@ The mitigations that reduce risk by type are: