Commit e23c7527 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Removed extra nodes from annex B

parent 1a941f46
Loading
Loading
Loading
Loading
+0 −56
Original line number Diff line number Diff line
@@ -4785,10 +4785,6 @@ Attacker may use unknown exploitable vulnerabilities in the product to harm the

Mitigations for **Likelihood**:

> NOTE: See Clause 5.2 Appropriate level of cybersecurity
> NOTE: See Clause 5.12 Limit attack surface
> NOTE: See Clause 5.13 Exploit mitigation

* Low to Very Low:
  * CYB_GENERAL low risk
  * CYB_OPS
@@ -4805,11 +4801,6 @@ Mitigations for **Likelihood**:

Mitigations for **Impact**:

> NOTE: See Clause 5.8 Integrity
> NOTE: See Clause 5.9 Confidentiality
> NOTE: See Clause 5.13 Exploit mitigation
> NOTE: See Clause 5.14 Monitoring

* Low to Very Low:
  * INT_CONF
  * INT_ROTATE
@@ -4854,10 +4845,6 @@ Attacker may use known exploitable vulnerabilities in the product implementation

Mitigations for **Likelihood**:

> NOTE: See Clause 5.3 No known exploitable vulnerabilities
> NOTE: See Clause 5.4 Secure updates
> NOTE: See Clause 5.5 Security updates

* Low to Very Low:
  * KEV_EXPLOIT
  * SBD_TECH
@@ -4872,12 +4859,6 @@ Mitigations for **Likelihood**:

Mitigations for **Impact**:

> NOTE: Same as TH-UEVU
> NOTE: See Clause 5.8 Integrity
> NOTE: See Clause 5.9 Confidentiality
> NOTE: See Clause 5.13 Exploit mitigation
> NOTE: See Clause 5.14 Monitoring

* Low to Very Low:
  * INT_CONF
  * INT_ROTATE
@@ -4922,9 +4903,6 @@ Attacker may get unauthorized access to product assets by exploiting gaps or wea

Mitigations for Likelihood:

> NOTE: See Clause 5.6 Authentication
> NOTE: See Clause 5.9 Confidentiality

* Low to Very Low:
  * AAC_AUTH
  * AAC_MACHINE
@@ -4941,9 +4919,6 @@ Mitigations for Likelihood:

Mitigations for Impact:

> NOTE: See Clause 5.9 Confidentiality
> NOTE: See Clause 5.14 Monitoring

* Low to Very Low:
  * CON_CRYPTO
  * CON_CHANNEL
@@ -4983,12 +4958,6 @@ Attacker may get unauthorized access to confidential data stored on the product

Mitigations for **Likelihood**:

> NOTE: See Clause 5.6 Authentication and access control
> NOTE: See Clause 5.9 Data minimisation
> NOTE: See Clause 5.13 Exploit mitigation
> NOTE: See Clause 5.12 Attack surface minimisation
> NOTE: See Clause 5.15 Factory reset

* Low to Very Low:
  * AAC_AUTH
  * AAC_MACHINE
@@ -5008,9 +4977,6 @@ Mitigations for **Likelihood**:

Mitigations for **Impact**:

> NOTE: See Clause 5.9 Confidentiality
> NOTE: See Clause 5.14 Monitoring

* Low to Very Low:
  * CON_CRYPTO
  * CON_CHANNEL
@@ -5050,10 +5016,6 @@ Attacker may use access to the connected network to compromise the confidentiali

Mitigations for **Likelihood**:

> NOTE: See Clause 5.8 Integrity
> NOTE: See Clause 5.9 Data minimisation
> NOTE: See Clause 5.9 Confidentiality

* Low to Very Low:
  * CON_CRYPTO
  * CON_CHANNEL
@@ -5070,9 +5032,6 @@ Mitigations for **Likelihood**:

Mitigations for **Impact**:

> NOTE: See Clause 5.9 Data minimisation
> NOTE: See Clause 5.14 Monitoring

* Low to Very Low:
  * DM_RETENTION
  * MON_LOG for low risk
@@ -5111,8 +5070,6 @@ Attacker may use unintentional configuration errors to get unauthorized access t

Mitigations for **Likelihood**:

> NOTE: See Clause 5.4 Secure by default configuration

* Low to Very Low:
  * SBD_TECH

@@ -5125,8 +5082,6 @@ Mitigations for **Likelihood**:

Mitigations for **Impact**:

> NOTE: See Clause 5.14 Monitoring

* Low to Very Low:
  * MON_LOG for low risk
  * MON_METRICS
@@ -5166,9 +5121,6 @@ Attacker may use network access to product to reduce availability of product fun

Mitigations for **Likelihood**:

> NOTE: See Clause 5.10 Availability protection
> NOTE: See Clause 5.11 Non-interference

* Low to Very Low:
  * AP_HA for low risk
  * IM_SEGMENT for low risk
@@ -5186,9 +5138,6 @@ Mitigations for **Likelihood**:

Mitigations for **Impact**:

> NOTE: See Clause 5.10 Availability protection
> NOTE: See Clause 5.14 Monitoring

* Low to Very Low:
  * MON_LOG for low risk
  * MON_METRICS
@@ -5229,9 +5178,6 @@ Attacker may use product functions to interfere with other devices or services.

Mitigations for **Likelihood**:

> NOTE: See Clause 5.10 Availability protection
> NOTE: See Clause 5.11 Non-interference

* Low to Very Low:
  * AP_HA for low risk
  * IM_SEGMENT for low risk
@@ -5249,8 +5195,6 @@ Mitigations for **Likelihood**:

Mitigations for **Impact**:

> NOTE: See Clause 5.14 Monitoring

* Low to Very Low:
  * MON_LOG for low risk
  * MON_METRICS