Manufacturer shall enable by default only the recommended designs that are fit for use-case. Any designs that are not fit for use-case may only be enabled after the user has been sufficiently informed of the security consequences in a manner that takes the use-case into account.
@@ -776,18 +789,11 @@ Reflecting to [List of Risk Factors](#451-list-of-risk-factors) defined in this
| [REQ-INGEST-0] | medium | medium | medium | medium |
| [REQ-INGEST-1] | high | medium | medium | high |
Note that in a closed system, where the confindentiality doesn't require transport encryption, the data integrity does require at least signing of the data set with cryptographically good enough keying.