@@ -675,9 +675,11 @@ None for the products in the scope of this document.
### C.2.1 General
Risk factors determine which mitigation(s) satisfy each of the cybersecurity requirements in clause 5.2. The assessor of a product determines the level of each risk factor via the development of a threat model and risk profile based on the intended and foreseeable use and misuse of the VPN.
Risk factors influence the likelihood or impact of a threat to a product asset. Thus, risk factors determine which mitigation(s) satisfy each of the cybersecurity requirements in clause 5.
Risk factors may increase the likelihood of an incident, increase the impact of an incident, or both. As a result, different mitigation strategies may be more or less relevant to different risk factors.
The creator of a product risk assessment determines the level of each risk factor via the development of a threat model and risk profile based on the intended purpose and foreseeable use of the VPN.
Risk factors may increase one or both of the likelihood and impact of a compromise. As a result, different mitigation strategies may be more or less relevant to different risk factors.
The overall risk related to each use case should be considered as a result of combining risk factors affecting both likelihood and impact of an incident.
The technical requirements of the present document apply under the product context described in [clause 4](#_clause.4), which shall be in accordance with its intended use. The product shall comply with all applicable technical requirements of the present document at all times when operating in such a product context.
Not all requirements are universally applicable: The applicability of requirements may be based on use cases described in clause 4.6 or specific capabilities of the product. Each requirement clearly indicates its applicability, and all requirements are mapped to use cases in Annex B.
Not all requirements are universally applicable: The applicability of requirements may be based on use cases described in clause 4.6 or specific capabilities of the product. Each requirement clearly indicates its applicability, and all requirements are mapped to use cases in Annex B. The applicability of requirements is based on the security analysis in Annex B, using the product assets and risk factors derived from the characteristics of each use case.
Some risks may be transferred partially or fully to other components of the system or the user of the product. When that is the case, mitigations that transfer the risk will be included as an option to fulfill a cybersecurity requirement, depending on the use case and risk factors.