@@ -1557,23 +1557,27 @@ Functional sufficiency assessment, “not necessary of a pure applicability requ
> Describe how to decide if residual risks are tolerable.
<mark>AMS: Pol and Santeri? focusing on vulnerability handling</mark>
## C.2 Risk assessment methodology
## C.2 Risk Assessment
Risk levels for each factors are determined by reading the descriptions for each risk factor and choosing the one that most accurately represents the highest risk for the intended purpose and reasonably foreseeable use and misuse of the product, as specified by the manufacturer.
> For each threat identified above, use likelihood and magnitude of the threat to assess its risk in the context of use cases. The results should be consistent with the mapping of use cases to security profiles.
The risks can be divided to likelihood and impact, but they can also be presented as a whole.
When likelihood and impact is presented, only high and low evaluation is available.
Risk is considred to medium, when one of the likelihood and impact is low, and the other one is high.
> Guidance from latest PT1 draft:
>
> An analysis in terms of likelihood and magnitude of a product’s threats is required to be able to determine the product’s risks.
When both likelihood and impact are low, the requirements defined in the chapter [5 Requirements specifications] defined for low category sets the minimum required features for any product within the category subject to this document.
> NOTE 1 This document does not require a specific methodology for a cybersecurity risk analysis as long as the cybersecurity risk estimation is based on the likelihood of occurrence and magnitude of loss or disruption of cybersecurity risks. Thus, different approaches and models such as the fishbone model, event tree analysis or fault tree models can be used within the analysis of cybersecurity risks.
When multiple risk factors are combined in a single requirement applicability, the highest risk level determines what is required from the product.
> NOTE 2 A qualitative estimation of the cybersecurity risks can be performed using risk matrices that map qualitative categories of the likelihood of occurrence and qualitative categories of magnitude of loss or disruption to cybersecurity risk categories.
To be able to map the product requirements applicability:
> NOTE 3 A quantitative estimation of the cybersecurity risks can be performed using scoring systems that map qualitative categories of the likelihood of occurrence and qualitative categories of magnitude of loss or disruption to certain values.
1. Document a comprehensive range of foreseeable use cases for products of this type.
1. Define the product risk levels evaluating the risk factors as low-mid-high based on the instructions.
1. Cross reference to [5 Requirements specifications] requirements.
1. See from [6 Conformity asssesments and tests] how to show conformity of the product.
> If any risks are not treated by the normative requirements, describe non-normative suggestions to mitigate them.
### C.2.4.2 Residual risk
> Describe how to treat any residual risks, for example by documenting them or informing the user.
## C.3 Assumptions
> List assumptions that are relevant to the risk analysis for these threats. Everything is hackable if you try hard enough, but what risks can this product mitigate, and what must it delegate to other components or the operational environment? Some potential examples:
>
> - An antivirus product assumes the operating system is not already compromised
> - No one will unplug the computer
> - The Baseboard Management Controller is not malicious
>
> Assumptions may vary by use case. For example, for a VPN, if the use case is protecting from a state actor, then you must assume focused, specific surveillance of all of the user's network traffic. If the use case is downloading a TV show only available in another country, you can assume that no one is analyzing the user's traffic.
- Proper operating system
- **Rationale:** A network management system requires a trustworthy operating system to perform its functions.
@@ -1713,8 +1696,6 @@ The manufacturer shall follow the CRAs pricibles of implementing high level of c
- Not using sophisticated or expensive hardware snooping techniques
- No secret hardware backdoors
<mark>FIXME list more assumptions</mark>
# Annex D (informative): Risk evaluation guidance
For each network management system placed on the market, the manufacturer shall develop a threat model and risk profile of the foreseeable use of the system, and shall consider the interplay between: