***AP_HA-5** The product shall implement coordinated brute‑force and overload protection mechanisms that not only detect excessive authentication attempts or inbound traffic surges but also enforce active mitigation actions including, but not limited to connection throttling, temporary IP blocking, message buffering, QoS parameterisation.
***AP_HA-5** The product shall implement coordinated brute‑force and overload protection mechanisms that not only detect excessive authentication attempts or inbound traffic surges, but also enforce active mitigation actions, including but not limited to connection throttling, temporary IP blocking, message buffering, and QoS parameterisation.
***AP_HA-6** The product shall implement recovery or failover mechanisms.
***AP_HA-7** If the product can be exposed to DDoS, the product shall implement DDoS mitigations like: