@@ -1295,7 +1295,7 @@ These requirements apply to the product, regardless of the product's use case an
* privileged function use
* data access and deletions
* data changes and permission changes.
***AAC_AUTH-9** The product shall verify successfully an explicit authorisation decision immediately before execution of any privileged action that can modify, including but not limited to:
***AAC_AUTH-9** The product shall explicit authorise any privileged action before its execution can modify, including but not limited to:
* managed-element configuration
* control-plane behaviour routing or forwarding state
* security policy
@@ -1659,7 +1659,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
Due to complexity, and industry wide use of various protocols and best practices, the support for data transfer is not required.
***DRT_DELETE-1** The product shall provide a function to remove all data and settings or support full re-install to restore to its secure-by-default state.
***DRT_DELETE-2**The product shall support an export and import of all of the relevant configuration, inventory and secrets that is used to configure the system.
***DRT_DELETE-2**If import and export of data is available, the related data transfer shall use a secure channel.
# 6 Assessment criteria for compliance with technical requirements