Commit ba1fe111 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Appended annex G with use-case guidance

parent 0f2c47ec
Loading
Loading
Loading
Loading
+10 −0
Original line number Diff line number Diff line
@@ -4711,6 +4711,16 @@ ETSI Standards referenced by this document:

# Annex G: Guidelines on the implementation of the present document (informative):

## G.0.1 The guidance header nummbering follows the document structure

This annex indexing is following the document structure, and is not intentioned to be incremental.

## G.4.6 Guidance on use-cases

It is not necessary to find a use case whose risks are identical to those identified by the product's cybersecurity risk assessment. If a use case has equal or higher risks to the product's, then it can be used. For example, a use case that includes the product being connected to a public network (a high level of this risk factor) can also be used for a product whose intended purpose is to be connected to a private network with a filtered connection to a public network.

New use cases may be added to the present document along with any new risks factors or requirements necessary to fully treat the risks, along with any necessary updates to the security analysis.

## G.5.3 Guidance on no known exploitable vulnerabilities requirements

If the deliverable contains or requires an operating system the operating system is expected to be regularly updated and maintained.