Commit bb54794a authored by Giulio Di Clemente's avatar Giulio Di Clemente
Browse files

Edit EN-304-624.md Annex B first modifications

parent 830ba001
Loading
Loading
Loading
Loading
+26 −2
Original line number Diff line number Diff line
@@ -2125,8 +2125,32 @@ Other Union legislation may be applicable to the product(s) falling within the s



# Annex B Mappings
## B.1 Mapping of threats to technical security requirements and their associated assessment requirements
# Annex B (informative): Cybersecurity threat landscape, risk identification and assessment methodology

This Annex applies a “state of the art” risk assessment methodology to the Product in scope of the present document, to identify threats, evaluate the risks and define security profiles applicable to the different use cases of the product context.

The general approach in the present document is taken from ETSI TS 102 165-1 [] (the TVRA method) with some refinements for the specific product.

## B.1 Risk calculation

Risk is calculated as the product of impact and likelihood. The metrics are derived from those given in clauses 5a and 6 of ETSI TS 102 165-1 [] modified as shown in tables B.1, B.2 and B.3 below. 

In assessing impact reasonable consideration has to be made for the use case in which the product is deployed which should include assessment of the following factors and as these are dependent on the specific use case the mitigations primarily consider limiting the likelihood of an attack:

- Deployment factors
- Network security factors
- User Expertise
- Operational security procedures
- Interfaces exposure

<div align="center">

**Table B.1: Impact metric for use in risk calculation modified from Table 3 of TS 102 165-1 []**
</br> 
</div>




![Figure B.1-1: Mapping of threats to technical and assessement requirement part 1](media/RequirementCoverage_P1_2026-01-08.png)