@@ -1677,7 +1677,7 @@ Review the technical documentation to confirm the scope of cybersecurity-relevan
#### 6.14.2.3 Activities
For each type of cybersecurity-relevant event, trigger the event, and collect any log messages
For each type of cybersecurity-relevant event, trigger the event, and collect any log messages.
#### 6.14.2.4 Verdict
@@ -2040,7 +2040,7 @@ Risk factor levels for each use case are determined by reading the descriptions
For each threat, a formula based on the risk factor levels is used to calculate the Likelihood and Impact of the threat, on a scale of Very Low, Low, Medium, and High.
For each threat, both likelihood and impact must be Very Low before the risk is considered sufficiently mitigated. If the calculated levels are not already Very Low, then mitigations must be applied until they are both Very Low. The set of requirements that will accomplish this are listed in each threat description.
For each threat, both likelihood and impact need to be Very Low before the risk is considered sufficiently mitigated. If the calculated levels are not already Very Low, then mitigations need to be applied until they are both Very Low. The set of requirements that will accomplish this are listed in each threat description.
For some threats, the risk analysis assigns the same requirements to treat more than one level of risk. When this occurs, it is because the same mitigation treats more than levels of risk and there is no lesser mitigation that treats the lower risk(s) but not the higher risk(s). Risk formulas like this could be simplified, but keeping the distinction between levels of risk may simplify the addition of new mitigations for lower risk cases.