Commit 23a75ed0 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Clause 5.1.4: Clarify cybersecurity-relevant guidance

parent a1063d36
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -819,7 +819,7 @@ NOTE: Annex R specifies supplementary requirements for the product-facing RDPS b

### 5.1.4 Guidance for "cybersecurity-relevant"

The term "cybersecurity-relevant" is used to allow the assessor to exclude some elements of the product from assessment if they are not relevant to the essential cybersecurity requirement being assessed. The exclusion must be documented with a clear reason. It is never required to identify which parts of the product are cybersecurity-relevant as long as all parts that are not excluded are assessed.
The term "cybersecurity-relevant" is intended to allow the assessor to exclude some elements of the product from assessment if they are not relevant to the essential cybersecurity requirement being assessed. The exclusion must be documented with a clear reason. It is not necessary to identify which parts of the product are cybersecurity-relevant with any precision (or at all) as long as all cybersecurity-relevant parts of the product are included in the assessment.

<mark>Editor’s Note: Each technical requirement should contain an applicability subclause as short as it might be. Example of the content of such an applicability subclause: “unconditionally applicable”, “applicable to UC-1 and UC-3”, “applicable if the product presents capability X,” “applicable to products of type X (subcategory of product category)”. Applicability subclauses may have compound criteria.</mark>