Removed note regarding duties to provide cybersecurity even where integrating...
Removed note regarding duties to provide cybersecurity even where integrating components per CRA sections. It could have been rephrased but the connection to data assets was quite unclear
@@ -1827,8 +1827,6 @@ The stored data can be, but is not limited to:
- Protocol analysis information
- Network configuration data
The manufacturer shall follow the CRAs priciples of implementing high level of cybersecurity of products [CRA Recital 11] [\[i.1\]](#_ref_i.1). The protection duty extends to third party integrations regardless of the market status of the component. [CRA Recital 34] [\[i.1\]](#_ref_i.1).
## C.2.2 Threats
> Based on the assets, what are the threats during: