@@ -2257,8 +2257,6 @@ Other Union legislation may be applicable to the product(s) falling within the s
This Annex applies a “state of the art” risk assessment methodology to the Product in scope of the present document, to identify threats, evaluate the risks and define security profiles applicable to the different use cases of the product context.
The general approach in the present document is taken from ETSI TS 102 165-1 [] (the TVRA method) with some refinements for the specific product.
## B.1 Risk calculation
Risk is calculated as the product of impact and likelihood. The metrics are derived from those given in clauses 5a and 6 of ETSI TS 102 165-1 [] modified as shown in tables B.1, B.2 and B.3 below.
@@ -3167,8 +3165,6 @@ The risk are then calculated and their applicability defined using the matrixes
</div>
<divalign="center">
**Table B.15: Risk evaluation part 3**
@@ -3396,21 +3392,6 @@ The risk are then calculated and their applicability defined using the matrixes
<divalign="center">
**Table B.16: Risk evaluation part 4**
@@ -3635,17 +3616,6 @@ The risk are then calculated and their applicability defined using the matrixes
<divalign="center">
**Table B.17: Risk evaluation part 5**
@@ -3750,8 +3720,6 @@ The risk are then calculated and their applicability defined using the matrixes
</tr>
<tr>
<td>T.GlobalMisbehaviourReportingTampering</td>
<td>A Remote attacker may exploit interactions between the MA and the EA or AA in order to modify global misbehaving detection information in order to force wrong reaction either on correct ITS-S station or misbehaving stations</td>
@@ -3868,24 +3836,6 @@ The risk are then calculated and their applicability defined using the matrixes
</div>
<divalign="center">
**Table B.18: Risk evaluation part 6**
@@ -4045,8 +3995,6 @@ ETSI Drafting rules do not allow footnotes. All footnotes in this Annex will hav
Note for Gisela, Clauses have been renumbered for consistency.
## K.1 State of the Art Cryptography (SOTA)
### K.1.1 Requirement
@@ -4058,8 +4006,6 @@ The product shall, by default, use State-of-the-Art cryptography algorithms list
> NOTE 3 Supporting evidence options that an algorithm, which is not included in CRY-SOTA, is applicable and suitable for the respective use case, are listed in the related assessment criteria ( K.1.2.1) clause.
### K.1.2 Assessment criteria
#### K.1.2.1 Assessment objective:
The purpose of this assessment case is (the conceptual assessment) whether the implemented algorithms are identified as CRY-SOTA.