Commit 0fda0fa4 authored by Giulio Di Clemente's avatar Giulio Di Clemente
Browse files

Edit EN-304-624.md End of B.1

parent 9ba42ad3
Loading
Loading
Loading
Loading
+34 −0
Original line number Diff line number Diff line
@@ -2161,6 +2161,40 @@ The core technical metrics for determination of the likelihood of a particular c



<div align="center">

**Table B.2: likelihood metric for use in risk calculation modified from table 4 of TS 102 165-1 []**
</br> 

| Value | Likelihood of occurrence | Modified likelihood | Explanation |
|---|---|---|---|
|1 (note)| Very unlikely to  | Low | According to up-to-date knowledge, there are no means of solving the technical difficulties to state the threat irrespective of the motivation or resources available to the attacker. |
|1| Unlikely to succeed | Low | According to up-to-date knowledge, a possible attacker needs to solve strong technical difficulties to state the threat or the motivation for an attacker is very low. |
|2| Possible (could succeed) | Medium | The technical requirements necessary to state this threat are not high and could be solved without significant effort; furthermore, there is a reasonable motivation for an attacker to perform the threat. |
|3| Likely to succeed | High | There are no sufficient mechanisms installed to counteract this threat and the motivation for an attacker is quite high. |
|3 (note)| Very likely to succeed | High | As for very likely but the threat is considered more imminent. |
|NOTE: The values assigned to "Very unlikely" and "Unlikely" are identical, similarly the values assigned to "Likely" and "Very likely" are identical. The rationale is that they represent extreme poles but, in each case, do not equate to risk escalation.|

</div>

Mitigations often concentrate on minimising the likelihood of a successful attack by strategies including attack surface minimisation, data minimisation and general strategies of least privilege access to product functionality.

Risk, as per TS 102 165-1 [] is calculated as the product of impact and likelihood and shown in Table B.3.

<div align="center">

**Table B.3: Risk as product of likelihood and impact from TS 102 165-1 []**
</br> 

| Value | Risk | Explanation | 
|---|---|---|
| 1, 2 | Minor | No essential assets are concerned, or the attack is unlikely. Threats causing minor risks have no primary need for counter measures. |
| 3, 4 | Major | Threats on relevant assets are likely to occur although their impact is unlikely to be fatal. Major risks should be handled seriously and should be minimized by the appropriate use of countermeasures. |
| 6, 9 | Critical	| The primary interests of the providers and/or subscribers are threatened and the effort required from a potential attacker's to implement the threat(s) is not high. Critical risks should be minimized with highest priority. |
|NOTE: Because risk is calculated as the product of likelihood and impact the values 5, 7 and 8 cannot occur.|
</div>

## B.2 Risk Assessment


# Annex C Risk acceptance criteria and risk management methodology (informative) (PT1 6.3)