@@ -128,7 +128,7 @@ The Harmonised Standard shall have appropriate transposition periods specified.
The Technical Body may propose different dates to the default ones (3, 6, 18). Technical Bodies who wish to propose different dates are advised to indicate this clearly in the approved committee draft.
@@ -229,7 +228,7 @@ For the purposes of the present document, the following terms apply:
For the purposes of the present document, the following abbreviations apply:
| Abbreviation | Description |
|------------ | ----------------- |
|--------------|----------------|
| OS | Operating System |
| IDP | Identity Provider |
@@ -392,7 +391,7 @@ Only products, which implement high risk profile can be offered for an entity cl
> List the essential functions of the product, including:
>
> - What it does during its intended or reasonably foreseeble use?
> - What it does during its intended or reasonably foreseeable use?
> - How its functions are configured?
> - How it keeps itself secure and functioning?
@@ -425,11 +424,11 @@ The technical requirements of the present document apply under the environmental
> Describe the classes of users for this product, as differentiated by sophistication in understanding and taking responsibility for security risks. More sophisticated users can be expected to follow more instructions and cope with higher levels of unmitigated risks. Suggestions:
>
> - General public
> - Children
> - Assistants to primary user
> - IT professionals
> - Systems integrators
> * General public
> * Children
> * Assistants to primary user
> * IT professionals
> * Systems integrators
## 4.9 Risk distribution among components
@@ -458,24 +457,12 @@ The technical requirements of the present document apply under the environmental
> - PT2 drafts, available in the [ETSI DocBox](https://docbox.etsi.org/CYBER/CYBER/CEN-CLC/JTC13/WG09)
> Why do we need security levels? Isn't the base operation the same, but the applicaton usage context different? Stricter security expectes more imlemented features.
<mark>FIXME define why and what levels to use</mark>
## 5.2 Use cases by security level
<mark>FIXME define use cases for all levels defined</mark>
# Annex A (informative): Mapping between the present document and CRA requirements
> Table mapping technical security requirements from Section 5 of the present document to essential cybersecurity requirements in Annex I of the CRA. The purpose of this is to help identify missing technical security requirements.
| **No** | **Description** | **Requirements of Regulation** | **Clause(s) of the present document** | **Use case** | **Condition** |
| 1 | | | | | |
| 2 | | | | | |
@@ -621,7 +608,7 @@ Harmonised Standard ETSI EN 304 621
**Requirement Conditionality:**
**U/C** Indicates whether the requirement is unconditionally applicable (U) or is conditional upon the manufacturer's claimed functionality of the equipment (C).
**Use case** Indicates whether the requirement is unconditionally applicable (U) or is conditional upon the manufacturer's claimed functionality of the equipment (C).
**Condition** Explains the conditions when the requirement is or is not applicable for a requirement which is classified "conditional".
@@ -650,7 +637,7 @@ Other Union legislation may be applicable to the product(s) falling within the s
The "Change history/Change request (history)" annex shall be included in every revised or amended harmonised standard and shall contain information concerning significant changes that have been introduced by it. It shall be presented as a table.