@@ -1461,9 +1461,11 @@ These are example data for which public statistics are available [i.17].
For **low** risk:
***AP_HA-1**System updates and changes shall not be considered as exceptions in the product general availability definition.
***AP_HA-1**Operating system, if part of the product, or product updates and changes shall not be considered as exceptions in the product general availability definition.
***AP_HA-2** The product shall emit security events about detected issues that affect the availability of the product and its provided services.
> NOTE: **AP_HA-1** clarifies a common measurement misrepresentation. The requirement extends the **SU_UPDATE-2**. Updates are part of the product availability regardless of what layer is being updated.
For **medium** risk:
***AP_HA-3** The product shall tolerate loss of resources within the limits of the defined availability.
@@ -3170,17 +3172,16 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
1.Study the technical documentation;
**Activities:**
1. Intentionally terminate randomly an NMS-internal process, a processing node or simulate a loss of a datacenter.
2. Repeat the previous step 1 enough often with varying scopes to demonstrate conformance.
1. Study the metrcis definition and define what would happen if a operating system update outside of the product context as defined in **SU_UPDATE-2**
**Verdict:**
1. Pass, if the effect of the loss of a chosen resource or process termination matches the availability and service description, and that the NMS meets the availability time period definitions.
1. Fail otherwise.
1. Pass, if the product availability definition does not list exceptional events that are not counted towards availability.