Commit d9fe96ec authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Fill out remainder of risk assessment!!!!

parent 8393af1d
Loading
Loading
Loading
Loading
+13 −7
Original line number Diff line number Diff line
@@ -2219,17 +2219,23 @@ This clause describes the metholodogy followed in the current text.
| MQSE   | CDTX, IDTX, SCUD, LOGG                   |
| AHHS   | NKEV, SCUD, SSDD, LMII, LMAS, LOGG, SDEF |

## D.3 Risks not treated by the requirements
## D.3 Risk acceptance criteria

No risks are untreated by the requirements.
If the Likelihood and Impact of a risk are already Low or have been reduced to Low by application of mitigations, then the risk is acceptable. Alternatively, the risk may be transferred to the user or the operational environment, given proper justification.

## D.4 Risk acceptance criteria
## D.4 Risks not treated by the requirements

> Describe how to decide if residual risks are tolerable.
For each risk untreated by the product itself, a corresponding mitigation has been created to explicitly permit the risk to be transferred to the user or operational environment. These are:

## D.5 Residual risks

> Describe how to treat any residual risks, for example by documenting them or informing the user.
  * MI-KEVD
  * MI-KEVM
  * MI-DPAH
  * MI-PDDI-1
  * MI-SUDC
  * MI-SUOE
  * MI-SUAO
  * MI-DOCC
  * MI-DOST

# Annex E: Explanation of the present document (informative only)