Commit 22dbc938 authored by Aeva Black's avatar Aeva Black Committed by Valerie Aurora
Browse files

Rewrite RF-SUPP

parent 9052e866
Loading
Loading
Loading
Loading
+6 −5
Original line number Diff line number Diff line
@@ -731,13 +731,14 @@ FIXME add the separate concept of users apart from accounts
* ADMN-1: foreseeable use always has skilled administrators available on call
* ADMN-2: foreseeable use may involve unskilled administrators

#### 4.5.1.x Length of support period
#### 4.5.1.x Support and forseeable Updates

**[RF-SUPP]:** How long the product is expected to be in use.
**[RF-SUPP]:** How long the product is expected to be in use, and whether the product is expected to be updated throughout its life cycle.

* SUPP-0: foreseeable use is for a length of time less than the time necessary to remediate a vulnerability
* SUPP-1: foreseeable use is for a length of time long enough to require remediating at least one vulnerability
* SUPP-2: foreseeable use is for a length of time long enough to require remediating multiple vulnerabilities
* SUPP-0: foreseeable use does not require that the operating system be updated at any point in its lifecycle
* SUPP-1: foreseeable use limits the installation of updates to skilled administrators with access to the operating system
* SUPP-2: foreseeable use includes the installation of updates by end-users with access to the operating system
* SUPP-3: forseeable use necessitates that the manufacturor provide frequent, automatic, and/or time-sensitive updates to the product, and may reasonably include a requirement for over-the-air updates.

### 4.5.2 Mapping of Use Cases to Risk Factors