@@ -1275,8 +1275,9 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
#### Generic requirements
All subjects require roles or comparable control structures like Attribute-Based Access Control, to limit individual access credentials to the smallest possible set of requested operations.
This is the reason for the requirement **AAC_AUTH-1**, but as the evaluating the fit of the implementation to the intended use, the design validation is specified in the requirement **AAC_AUTH-5**.
The product assigns to each subject a role or attributes based on the subject’s identity, to enable for the application of access control structures.
The access rights are thereby minimized to allow only for those operations that are needed for the intended use or task.
The assignment of access rights is the justification of the **AAC_AUTH-1** requirement, the matching of the control structure implementation with the intended use is covered with the requirement **AAC_AUTH-5**.
These requirements apply to the product, regardless of the product's use case and without variation for different tiers or risk.