Commit ab99a5c8 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Updated 6.15.1 DRT_DELETE-1 objective and added missing 6.15.2 DRT_DELETE-2 assessment

Closes #609, #610
parent 4346c644
Loading
Loading
Loading
Loading
+28 −1
Original line number Diff line number Diff line
@@ -4084,7 +4084,7 @@ Outcomes:

### 6.15.1 DRT_DELETE-1

**Objective:** Remove
**Objective:** The product user can remove all of his data from the product.

**Preparation:**

@@ -4110,6 +4110,33 @@ Outcomes:
* Logs, configuration files, or audit traces demonstrating the implementation of the requirement;


### 6.15.2 DRT_DELETE-2

**Objective:** If applicable, the product user can import or export data with a secure channel.

**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials.
2. Study the technical documentation
3. Change the product state in a way that generates stored data and generate outside the product a data set

**Activities:**

1. Export the previously in-product generated data and verify that a secure protocol as out of CON_CRYPTO-1 is deployed
2. Import the externally present data set and verify that a secure protocol as out of CON_CRYPTO-1 is deployed

**Verdict:**

1. Pass, if for import and export a protocol as of **CON_CRYPTO-1** is deployed
2. Fail otherwise.

**Supporting Evidence:**

* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
* Logs, configuration files, or audit traces demonstrating the implementation of the requirement;

# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 - the Cyber Resilience Act

The present document has been prepared in response to the Commission's standardisation request C(2025)618 [\[i.3\]](#_ref_i.3) to provide, in addition to its other uses, one voluntary means of conforming to the essential requirements of Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2) known as the Cyber Resilience Act (CRA).