@@ -2172,6 +2172,8 @@ Other Union legislation may be applicable to the product(s) falling within the s
# Annex B (informative): Security analysis
## B.0 Overview
This Annex applies state of the art methodology to identify assets, threats, identify and evaluate risk factors, and associate risk factor levels with different use cases identified in the product context. This security analysis informs the applicability of the technical requirements.
The security analysis in this Annex represents a risk assessment done by the standardisers solely for the purpose of informing the applicability of technical requirements.
@@ -2186,24 +2188,17 @@ For each threat, a formula based on the risk factor levels is used to calculate
* Provision cryptographic material (network access, management, packet encryption)
* Generate log messages
### B.1.3 Hardware
* Physical transmission media interface
* Connection to host system
* Processors
* Memory
## B.2 Risk factors
### B.2.1 List of risk factors
@@ -2347,7 +2350,7 @@ An attacker will have only temporary physical access to the product.
### B.3.5 Attacker has limited resources
An attacker has the resources available to a small group of skilled individuals, without the backing of large corporations, nation-states, or immense wealth.
An attacker will use limited resources in proportion to the value of the assets of the product in each use case.