@@ -1422,7 +1422,9 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
For **low** risk:
***EMM_ROUTE-1** The product shall be configurable to enforce granular packet filtering by managed element or server identity, and destination address when creating a connection with a managed element.
***EMM_ROUTE-1** Where management connections to managed elements are not wholly contained within a dedicated trusted management segment documented per **IM_SEGMENT** and **CYB_OPS-1**, the product or documented operational environment shall enforce controls that limit management traffic by managed element or server identity and destination address, appropriate to the intended and reasonably foreseeable use.
> NOTE:
For **medium** risk:
@@ -3404,7 +3406,7 @@ Verify that:
**Verdict:**
1. Pass, if filtering can be as described in the requirement.
1. Pass, if documented controls demonstrably limit management traffic by managed element identity and destination for the deployment model, or if non-applicability is justified per **IM_SEGMENT** and CYB_OPS-1.