1.**REQ-EM-01 (MI-SCFS)-1** Products shall incorporate built-in exploit mitigation mechanisms appropriate to the target platform and language (e.g., Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP/NX), or Stack Canaries), and
2.**REQ-EM-01 (MI-SCFS)-2** any exceptions to these mitigations shall be documented as to how each exception does not create an unacceptable risk.
#### 5.13.2.2 Applicability
TODO
### 5.13.3 Additional requirements
The following requirements also address this essential cybersecurity requirement using the same applicability:
* 5.10.5 REQ-AP-04 (MI-WDOG): Watchdog and self-initiated reset
* 5.10.6 REQ-AP-05 (MI-NTFY): Watchdog and notification of host
### 5.2.15 ER-LOGG: Logging and monitoring
#### 5.2.15.1 Cybersecurity requirement
@@ -2397,6 +2422,41 @@ Otherwise FAIL
A number of tools and techniques may be used to search for exposed interfaces, including network scanners, scanning a device's mapped memory regions on the system bus, penetration testing software suites, packet sniffers, snooping on various busses, and examining source code and configuration. A search plan does not need to be able to find all possible undocumented interfaces, only those that would found by a threat actor under the conditions of the manufacturer's cybersecurity risk assessment. An element of the rationale for an interface search plan might be "This scanning suite is the most complete version used by professional vulnerability researchers."
## 6.13 Exploit mitigation
### 6.13.1 Overview
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (k).