@@ -2147,26 +2147,21 @@ In assessing impact reasonable consideration has to be made for the use case in
**Table B.1: Impact metric for use in risk calculation modified from Table 3 of TS 102 165-1 []**
</br>
</div>
| Impact | Explanation | Value |
|---|---|---|
| Low | The concerned party is not harmed very strongly; the possible damage is low. For the product this is modified to mean "negligible impact to the organisation" | 1 |
| Medium |The threat addresses the interests of providers/subscribers and cannot be neglected. For the product this is modified to mean "significant impact to the organisation, negligible impact to the sector"| 2 |
|High| A basis of business is threatened and severe damage might occur in this context. For the product this is modified to mean "Severe impact to the organisation, significant impact to the sector" | 3 |

**Figure B.1-1: Mapping of threats to technical and assessement requirement part 1**
</div>

**Figure B.1-2: Mapping of threats to technical and assessement requirement part 2**
The core technical metrics for determination of the likelihood of a particular cyber-attack are defined in clause B.6 of the Common Criteria Evaluation methodology [] and further developed in clause 6.7 of TS §102 165-1 [] and then updated as shown in table B.2 of the present document. As identified in both the Common Criteria Evaluation methodology [] and in TS 102 165-1 [] an assessment of the likelihood of an attack is assessed from evaluation of a number of attributes of the attack and attacker including Time, Expertise, Knowledge, Opportunity, Equipment and motivation.

**Figure B.1-3: Mapping of threats to technical and assessement requirement part 3**

**Figure B.1-4: Mapping of threats to technical and assessement requirement part 4**
# Annex C Risk acceptance criteria and risk management methodology (informative) (PT1 6.3)