@@ -1284,6 +1284,30 @@ B.6 Mapping of risk factors to security profiles
# Annex K (normative): Generic requirements and assessment criteria for the use of state of the art cryptography
# Annex R (normative): Additional provisions for products relying on remote data processing solutions (RDPS)
## R.1 Scope & Applicability
This annex specifies additional technical requirements and assessment provisions for products with digital elements that rely on remote data processing solutions (“RDPS”) for the provision or support of one or more product functions.
The requirements applicable to the product functions themselves remain specified in the core part of the concerned standard and continue to apply to the product as a whole, including where a product function is performed locally, supported by an RDPS, or performed in part through an RDPS.
This annex specifies supplementary requirements and assessment provisions for the product-facing RDPS boundary, i.e. for the additional attack surface, interactions, and dependency conditions introduced where a product function is performed or supported across the local product side and the RDPS side.
Where the product does not rely on remote data processing solutions for the provision or support of any product function, this annex is not applicable.
This annex does not extend to the full remote service environment or underlying third-party infrastructure, except to the extent necessary to define assumptions, dependencies, and assessment conditions relevant to the product-facing RDPS boundary and the secure operation of the RDPS-dependent product function.
## R.2 RDPS as a product-boundary extension
## R.3 Threat Model
## R.4 Security Requirements
## R.5 Conformity assessment
## R.6 Mapping of CRA Annex I to Annex R requirements
# History
_The following table will automatically be filled in by the ETSI Secretariat._