Commit 120c29a1 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Fill in risk factors for confidentiality of stored data

parent 1e282fe3
Loading
Loading
Loading
Loading
+6 −8
Original line number Diff line number Diff line
@@ -1032,8 +1032,6 @@ Guidance: This is for the use case of an end user in use cases where network acc

The product shall be securely updateable by the user.

> FIXME add versions for device driver and virtual network interface.

#### 5.2.X.x **MI-SUDC**: Documentation of secure update

The product shall be accompanied by documentation of the secure update methods for any firmware or software in the product.
@@ -1111,14 +1109,14 @@ Guidance: Data may be protected by the environment, permissions, encryption, sal
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles

| Risk factors      | Requires mitigations |
|--------------|----------------------|
| SNDS < 1     | none                 |
|-------------------|----------------------|
| SDS < 1 & COM < 2 | none                 |
| all others        | CDST                 |

| Security Profile | Requires mitigations |
|------------------|----------------------|
| LR, IoT-1        | none                 |
| all others       | CDST                 |
| WD-\*            | none                 |
| WL-\*, VI-\*     | CDST                 |

### 5.2.X **TR-CDTX**: Confidentiality of data transmitted by product