Commit 1252a88e authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Minor formatting/wording fixes from Kim Nordstrom

parent c0e1baf1
Loading
Loading
Loading
Loading
+4 −4
Original line number Diff line number Diff line
---
Title: Cybersecurity (CYBER); CRA; Cybersecurity requirements for security information and event management (SIEM) systems
Title: Cyber Security (CYBER); CRA; Cybersecurity requirements for security information and event management (SIEM) systems
Spec Number: 304 622
Version: v0.2.1
Date: 2026-07-19
Release: 5
Work Item: WI-0010
keywords: CRA SIEM incident event management
keywords: CRA Cybersecurity SIEM incident event management
Copyright Year: 2026
---

@@ -1677,7 +1677,7 @@ Review the technical documentation to confirm the scope of cybersecurity-relevan

#### 6.14.2.3 Activities

For each type of cybersecurity-relevant event, trigger the event, and collect any log messages
For each type of cybersecurity-relevant event, trigger the event, and collect any log messages.

#### 6.14.2.4 Verdict

@@ -2040,7 +2040,7 @@ Risk factor levels for each use case are determined by reading the descriptions

For each threat, a formula based on the risk factor levels is used to calculate the Likelihood and Impact of the threat, on a scale of Very Low, Low, Medium, and High.

For each threat, both likelihood and impact must be Very Low before the risk is considered sufficiently mitigated. If the calculated levels are not already Very Low, then mitigations must be applied until they are both Very Low. The set of requirements that will accomplish this are listed in each threat description.
For each threat, both likelihood and impact need to be Very Low before the risk is considered sufficiently mitigated. If the calculated levels are not already Very Low, then mitigations need to be applied until they are both Very Low. The set of requirements that will accomplish this are listed in each threat description.

For some threats, the risk analysis assigns the same requirements to treat more than one level of risk. When this occurs, it is because the same mitigation treats more than levels of risk and there is no lesser mitigation that treats the lower risk(s) but not the higher risk(s). Risk formulas like this could be simplified, but keeping the distinction between levels of risk may simplify the addition of new mitigations for lower risk cases.