@@ -3223,7 +3223,7 @@ In assessing impact reasonable consideration has to be made for the use case in
</div>
The core technical metrics for determination of the likelihood of a particular cyber-attack are defined in clause B.6 of the Common Criteria Evaluation methodology [] and further developed in clause 6.7 of TS §102 165-1 [] and then updated as shown in table B.2 of the present document. As identified in both the Common Criteria Evaluation methodology [] and in TS 102 165-1 [] an assessment of the likelihood of an attack is assessed from evaluation of a number of attributes of the attack and attacker including Time, Expertise, Knowledge, Opportunity, Equipment and motivation.
<divalign="center">
@@ -3241,24 +3241,6 @@ The core technical metrics for determination of the likelihood of a particular c
</div>
Mitigations often concentrate on minimising the likelihood of a successful attack by strategies including attack surface minimisation, data minimisation and general strategies of least privilege access to product functionality.
Risk, as per TS 102 165-1 [] is calculated as the product of impact and likelihood and shown in Table B.3.
<divalign="center">
**Table B.3: Risk as product of likelihood and impact from TS 102 165-1 []**
</br>
| Value | Risk | Explanation |
|---|---|---|
| 1, 2 | Minor | No essential assets are concerned, or the attack is unlikely. Threats causing minor risks have no primary need for counter measures. |
| 3, 4 | Major | Threats on relevant assets are likely to occur although their impact is unlikely to be fatal. Major risks should be handled seriously and should be minimized by the appropriate use of countermeasures. |
| 6, 9 | Critical | The primary interests of the providers and/or subscribers are threatened and the effort required from a potential attacker's to implement the threat(s) is not high. Critical risks should be minimized with highest priority. |
> NOTE: Because risk is calculated as the product of likelihood and impact the values 5, 7 and 8 cannot occur.
</div>
## B.2 Risk Assessment
### B.2.1 Likelihood risk factors
@@ -3272,18 +3254,15 @@ Risk, as per TS 102 165-1 [] is calculated as the product of impact and likeliho
<tdstyle="padding:7px; border:1px solid #ccc; background:#00B050; color:green; font-weight:bold; text-align:center;">Consumer use or non-critical use in enterprises</td>
<tdstyle="padding:7px; border:1px solid #ccc; background:#00B050; color:green; font-weight:bold; text-align:center;">Consumer use or non-critical use in enterprises.</td>
<tdstyle="padding:7px; border:1px solid #ccc; background:#FF0000; color:red; font-weight:bold; text-align:center;">Critical use in enterprises (NIS2) or public PKI use case</td>
<tdstyle="padding:7px; border:1px solid #ccc; background:#FFD700; color:yellow; font-weight:bold; text-align:center;">Product use in critical environmment.</td>
</tr>
</table>
</div>
@@ -3621,17 +3600,9 @@ The following figures present the impact factors evaluation for the 4 use cases
</tr>
</table>
</div>
## B.4 Evaluate Risks
This clause presents the evaluation of the risk factors for each of the use cases. The following tables evaluate the risks for each use case related to threats defined in clause 4. For each threat the list of associated risk factors values are assessed and for each combination of factors a maximum function is applied (the resulting impact or likelihood level is the maximum of all risk factors levels).