@@ -2125,8 +2125,32 @@ Other Union legislation may be applicable to the product(s) falling within the s
# Annex B Mappings
## B.1 Mapping of threats to technical security requirements and their associated assessment requirements
# Annex B (informative): Cybersecurity threat landscape, risk identification and assessment methodology
This Annex applies a “state of the art” risk assessment methodology to the Product in scope of the present document, to identify threats, evaluate the risks and define security profiles applicable to the different use cases of the product context.
The general approach in the present document is taken from ETSI TS 102 165-1 [] (the TVRA method) with some refinements for the specific product.
## B.1 Risk calculation
Risk is calculated as the product of impact and likelihood. The metrics are derived from those given in clauses 5a and 6 of ETSI TS 102 165-1 [] modified as shown in tables B.1, B.2 and B.3 below.
In assessing impact reasonable consideration has to be made for the use case in which the product is deployed which should include assessment of the following factors and as these are dependent on the specific use case the mitigations primarily consider limiting the likelihood of an attack:
- Deployment factors
- Network security factors
- User Expertise
- Operational security procedures
- Interfaces exposure
<divalign="center">
**Table B.1: Impact metric for use in risk calculation modified from Table 3 of TS 102 165-1 []**
</br>
</div>
