@@ -4711,6 +4711,16 @@ ETSI Standards referenced by this document:
# Annex G: Guidelines on the implementation of the present document (informative):
## G.0.1 The guidance header nummbering follows the document structure
This annex indexing is following the document structure, and is not intentioned to be incremental.
## G.4.6 Guidance on use-cases
It is not necessary to find a use case whose risks are identical to those identified by the product's cybersecurity risk assessment. If a use case has equal or higher risks to the product's, then it can be used. For example, a use case that includes the product being connected to a public network (a high level of this risk factor) can also be used for a product whose intended purpose is to be connected to a private network with a filtered connection to a public network.
New use cases may be added to the present document along with any new risks factors or requirements necessary to fully treat the risks, along with any necessary updates to the security analysis.
## G.5.3 Guidance on no known exploitable vulnerabilities requirements
If the deliverable contains or requires an operating system the operating system is expected to be regularly updated and maintained.