Commit 7351f68d authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Clarify requirement inheritance in risk assessment

parent 986519cd
Loading
Loading
Loading
Loading
+4 −4
Original line number Diff line number Diff line
@@ -1849,7 +1849,7 @@ Attacker may use known exploitable vulnerabilities in the product implementation

Requirements that mitigate this threat: NKEV, SSDD, LMII, SCUD, DMIN, LMAS, LOGG, VULH

All mitigations from TH-UEVU apply, in addition to:
All mitigations from TH-UEVU apply (using that requirement's risk formula), in addition to:

Mitigations for Likelihood:

@@ -1965,7 +1965,7 @@ Attacker may exploit vulnerabilities in the product to reduce availability of pr

Requirements that mitigate this threat: NKEV, AVAI, LMII, LMAS, LOGG, VULH

All mitigations for TH-KEVU apply, plus:
All mitigations for TH-KEVU apply (using that requirement's risk formula), plus:

Mitigations for Impact:

@@ -2021,7 +2021,7 @@ Attacker may exploit vulnerabilities in the product to attack other products.

Requirements that mitigate this threat: NKEV, LMII, MINI, LMAS, LOGG, VULH

All mitigations from TH-KEVU apply, plus:
All mitigations from TH-KEVU apply (using that requirement's risk formula), plus:

Mitigations for Impact:

@@ -2079,7 +2079,7 @@ _Note: If the attacker has physical or host system software access, they don't n

Requirements that mitigate this threat: NKEV, SSDD, LMII, SCUD, AUTH, LMAS, LOGG

All mitigations from TH-KEVU apply, plus:
All mitigations from TH-KEVU apply (using that requirement's risk formula), plus:

Mitigations for Likelihood: