Commit 476e1ec4 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Remove obsolete clause 5.2.18 Vulnerability handling

This is outside the scope of the vertical standard according to
ETSI/EC comments.
parent 4b93a762
Loading
Loading
Loading
Loading
+0 −17
Original line number Diff line number Diff line
@@ -1673,23 +1673,6 @@ If the product provides a method to transfer data and settings to another produc

See clause 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.

### 5.2.18 ER-VULH: Vulnerability handling

#### 5.2.18.1 Cybersecurity requirement

The product shall have vulnerability handling processes compliant with prEN 40000-1-3 [\[3\]](#_ref_3).

#### 5.2.18.2 MI-VULH: Vulnerability handling

The product shall have vulnerability handling processes compliant with prEN 40000-1-3 [\[3\]](#_ref_3)\.

  * Applicability: (for cybersecurity requirements that depend on a feature)
  * Reference: ER-VULH
  * Objective: Vulnerability handling
  * Activities: Review documentation associated with vulnerability handling.
  * Verdict: Vulnerability handling documentation is compliant with prEN 40000-1-3 [\[3\]].(#_ref_3) => PASS, otherwise FAIL
  * Evidence: Vulnerability handling documentation, comparison with  prEN 40000-1-3 [\[3\]](#_ref_3).

## 5.3 Security Profiles

This clause lists all the mitigations necessary to meet cybersecurity requirements for each security profile.