@@ -529,15 +529,15 @@ Indirect users of network interfaces include:
## 4.6 Use Cases
<mark>Editor's Note: The use cases shall be defined as a combination of the product context elements described in clauses 4.1 to 4.5, clearly indicating:<br>
- Title the title of the use case, following a consistent naming/ID scheme (e.g., UC-3 Internet Connection)<br>
- Goal the goal of the use case (e.g., connect to the Internet)<br>
- Description via subclauses or bullet points which elements from each apply (i.e., product type: ..., function: ..., users: ..., architecture: ..., operational environment: ...)
</mark>
### 4.6.1 Overview
Use cases are defined in terms of risk factor levels that determine which requirements in Clause 5 must be satisfied to reduce the cybersecurity risks of the product to an acceptable level.
The manufacturer designates an intended purpose for the product. This intended purpose and its reasonably foreseeable use may be used to select a use case with risks that are fully treated by the associated requirements.
<mark>Editor’s Note: The standard may only be applied to those use cases listed in the standard. To ensure borad applicability, use cases should strive to covr all use cases known to the stnadardisers, with a view to aiming for full reflection of market realities. This can be achieved by staying at a level of abstraction granular enough to serve as basis for security analysis.</mark>
While it is possible to list every possible combination of risk factor levels, the use cases addressed in this section are intended to represent useful and common categories of products.
<mark>Editor’s Note: Use cases may include the case of critical infrastructure but shall refrain from an explicit link to the NIS 2 Directive.</mark>
New use cases may be added along with any new risk factors or requirements necessary to fully treat the risks.