Commit 936ca809 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Format/add missing requirements to threats

parent bea93e4b
Loading
Loading
Loading
Loading
+4 −4
Original line number Diff line number Diff line
@@ -716,7 +716,7 @@ Attacker may use known exploitable vulnerabilities in the product implementation
| max(DAT, FUN, COM) > 0 | High   | SP-2, SP-3, SP-4  |
| all others             | Medium | SP-1              |

Requirements that mitigate this threat: NPII, LOGG, VULH
Requirements that mitigate this threat: NKEV, SSDD, NPII, LOGG, VULH

All mitigations from TH-UEVU apply (using that requirement's risk formula), in addition to:

@@ -742,7 +742,7 @@ Attacker may gain unauthorized access to an endpoint in a manner not under contr
| all others        | Medium | SP-2, SP-4        |
| DAT = 0 & FUN = 0 | Low    | SP-1              |

Requirements: AUTH, DMIN
Requirements that mitigate this threat: AUTH, DMIN

Mitigations for Likelihood:

@@ -802,7 +802,7 @@ Attacker may read or modify traffic by capturing and relaying activity to and fr
| all others        | Medium | SP-2, SP-4        |
| DAT = 0 & FUN = 0 | Low    | SP-1              |

Requirements: CRYPT, NPII, LOGG
Requirements that mitigate this threat: CRYPT, NPII, LOGG

Mitigations for Likelihood:

@@ -919,7 +919,7 @@ Attacker may remove evidence of compromise from the endpoint.
| all others        | Medium | SP-2, SP-4        |
| DAT = 0 & FUN = 0 | Low    | SP-1              |

Requirements that mitigate this threat: LOGG
Requirements that mitigate this threat: LOGG, NPII

Mitigations for Likelihood: