Commit c3ff99c3 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Removing Annex C (optional)

parent 6a158699
Loading
Loading
Loading
Loading
+0 −136
Original line number Diff line number Diff line
@@ -4039,142 +4039,6 @@ The risk are then calculated and their applicability defined using the matrixes
</Table>
</div>

# Annex C (Informative) Relationship between the present document and any related ETSI standards (if any, e.g. EN 303 645)

Add reference to mappings for eIDAS and C-ITS from each of ETSI TC ESI and ETSI TC ITS (WG5)
-----------------------------------------------------------------------------------------------------------------------------
## C.1 Risk acceptance + risk management methodology

### C.1.1 Riks levels calculation

To calculate the risk we use the following tables, where in the matrix presented in Figure C.1.1-3, we define how the impact (Figure C.1.1-1) and likelihood (Figure C.1.1-2) associated to a risk are combined to calculate the final risk value.

Later on in sections C.1.2 and C.1.3 we further define for the different use cases the impact factors to define these likelihood and impact values.

As a remainder the 4 use cases define in the standard are:
- UC1:	Private PKI for non-critical entities
- UC2:	Private PKI for critical entities
- UC3:	Public CA PKI software
- UC4:	C-ITS PKI

![Figure C.1.1-1: Impact scale](media/ImpactScale.png)

**Figure C.1.1-1: Impact scale**

![Figure C.1.1-2: Likelihood scale](media/LikelihoodScale.png)

**Figure C.1.1-2: Likelihood scale**

![Figure C.1.1-3: Risk calculation matrix](media/RiskCalculationMatrix.png)

**Figure C.1.1-3: Risk calculation matrix**

### C.1.2 Risk acceptance threshold

![Figure C.1.2-1: Risk acceptance threshold](media/RiskAcceptanceThreshold.png)

**Figure C.1.2-1: Risk acceptance threshold**



## C.2 Risk Assessment
### C.2.1 Estimate Risks (Risk factors)
#### C.2.1.1 Likelihood risk factors

The following figures present the likelihood factors for the 4 use cases used to caclulate risks. They are categorised as follow :

- Deployment factors
- Network security factors
- User Expertise
- Operational security procedures
- Interfaces exposure


![Figure C.2.1.1-1: Risk factor dep](media/RiskFactorDep.png)

**Figure C.2.1.1-1: Risk factor dep**

![Figure C.2.1.1-2: Risk factor net](media/RiskFactorNet.png)

**Figure C.2.1.1-2: Risk factor net**

![Figure C.2.1.1-3: Risk factor user](media/RiskFactorUsr.png)

**Figure C.2.1.1-3: Risk factor user**

![Figure C.2.1.1-4: Risk factor ops](media/RiskFactorOps.png)

**Figure C.2.1.1-4: Risk factor ops**

![Figure C.2.1.1-5: Risk factor int](media/RiskFactorInt.png)

**Figure C.2.1.1-5: Risk factor int**

#### C.2.1.2  Impact risk factors

The following figures present the impact factors evaluation for the 4 use cases used to caclulate risks. They are categorised as follow :

- Availability
- Integrity
- Confidentiality
- and Traceability


![Figure C.1.3-1: Risk factor ava](media/RiskFactorAva.png)

**Figure C.1.3-1: Risk factor availability**

![Figure C.1.3-2: Risk factor in](media/RiskFactorIn.png)

**Figure C.1.3-2: Risk factor integrity**

![Figure C.1.3-3: Risk factor conf](media/RiskFactorConf.png)

**Figure C.1.3-3: Risk factor confidentiality**

![Figure C.1.3-4: Risk factor tra](media/RiskFactorTra.png)

**Figure C.1.3-4: Risk factor traceability**

#### C.2.1.2 Impact risk factors

## C.2.2 Risk analysis

In this section we present the evaluation of the riks factors for each of the 4 use cases.

In the table we evaluate the risks for each use cases related to threats defined in section 4. For each threats the list of associated risk factors values are assessed and for each combinaison of factors a maximum function is applied (the resulting impact or likelihood level is the maximum of all risk factors levels).

The risk are then calculated and their applicability defined using the matrixes presented in Figure C.1.1-3 and Figure C.1.2-1.

![Figure C.2.2-1: Risk evaluation part 1](media/RiskEvaTab_1_2026-01-06.png)

**Figure C.2.2-1: Risk evaluation part 1**

![Figure C.2.2-2: Risk evaluation part 2](media/RiskEvaTab_2_2026-01-06.png)

**Figure C.2.2-2: Risk evaluation part 2**

![Figure C.2.2-3: Risk evaluation part 3](media/RiskEvaTab_3_2026-01-06.png)

**Figure C.2.2-3: Risk evaluation part 3**

![Figure C.2.2-4: Risk evaluation part 4](media/RiskEvaTab_4_2026-01-06.png)

**Figure C.2.2-4: Risk evaluation part 4**

![Figure C.2.2-5: Risk evaluation part 5](media/RiskEvaTab_5_2026-01-06.png)

**Figure C.2.2-5: Risk evaluation part 5**

![Figure C.2.2-6: Risk evaluation part 6](media/RiskEvaTab_6_2026-01-06.png)

**Figure C.2.2-6: Risk evaluation part 6**

-----------------------------------------------------------------------------------------------------------------------------




# Annex K (normative): Generic requirements and assessment criteria for the use of state of the art cryptography V 0.51 (2025-02-16)

ETSI Drafting rules do not allow footnotes. All footnotes in this Annex will have to be deleted or replaced by relevant references and notes before publication.