@@ -2355,32 +2355,53 @@ The risk modeling approach followed in this document can be applied to two situa
**Methodology**
This section describes the metholodogy followed in the current text.
This clause describes the methodology followed in the current text.
1. Document a comprehensive range of foreseeable use cases for products of this type.
1. For a particular use case, document the inherent and product-specific risk factors likely to affect products of that type which are not already covered by other relevant standards.
1. For that use case, document environmental risk factors likely to affect products of that type which are not already covered by other relevant standards.
1. For each risk factor identified in the prior two steps, document appropriate mitigations which should be present to mitigate the specific risk. If multiple mitigations relate to a common risk factor, indicate a risk-based prioritization to provide guidance on when each mitigation is appropriate. For each mitigation, also document at least one verification methodology.
1. Document a comprehensive list of threats. For each threat, create a formula to estimate the risk level using the risk factors.
1. For each threat, document appropriate mitigations which should be present to mitigate the specific risk depending on the risk level. For each mitigation, also document at least one verification methodology.
1. Create a mapping between each use case and each risk factor, assigning a proportionality score. The scoring range should start from zero, representing the inapplicability of a risk factor to a use case, and increase monotonically based on both the likelihood and severity of potential harm or impact.
1. For each use case, verify that the proportional risk score (relative to other use cases) is informational. For example, use cases that are expected to pose little risk of harm, in the event of a cybersecurity incident, to the end user should have a lower score than use cases which are expected to pose higher risk of harm. This score is subjective and informative only.
1. Combine the output of the prior two steps to derive the completed list of required mitigations for each use case.
1. Develop security profiles from the use cases, which are collections of risk factor levels that can be used to fully describe the risk levels of all relevant threats. There may be one use case per security profile or multiple. There should be as many security profiles as are useful to manufacturers.
1. Using the risk factors in the security profiles and the risk formulas and mitigations for all threats, derive the completed list of required mitigations for each security profile.
## D.2 Mapping of risks to requirements
> Table mapping the identified risks to requirements
> If any risks are not treated by the normative requirements, describe non-normative suggestions to mitigate them.
If the Likelihood and Impact of a risk are already Low or have been reduced to Low by application of mitigations, then the risk is acceptable. Alternatively, the risk may be transferred to the user or the operational environment, given proper justification.
## D.4 Risk acceptance criteria
## D.4 Risks not treated by the requirements
> Describe how to decide if residual risks are tolerable.
For each risk untreated by the product itself, a corresponding mitigation has been created to explicitly permit the risk to be transferred to the user or operational environment. These are:
## D.5 Residual risks
> TODO: update below
> Describe how to treat any residual risks, for example by documenting them or informing the user.