@@ -1468,11 +1468,13 @@ The product shall detect corruption of the data transmitted by the product.
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
#### 5.2.X.x Requirement
### 5.2.12 TR-DMIN: Data Minimization
#### 5.2.12.1 Requirement
The product shall minimize the data processed.
#### 5.2.X.x **MI-DJST**: Document and justify processed data
#### 5.2.12.2 MI-DJST: Document and justify processed data
All sources of data processed by the product in its secure-by-default configuration shall be documented. All sources of data processed shall have a documented rationale for why its processing is necessary for the functioning of the product in its secure-by-default configuration.
@@ -1488,20 +1490,9 @@ All sources of data processed by the product in its secure-by-default configurat
* Evidence: List of sources of data, documentation of each source of data, list of sources of data processed, connection between each discovered source of processed data to its documentation
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles
| Risk factors | Requires mitigations |
|---------------------|----------------------|
| RT-High | none |
| SNDS < 1 & SNDT < 1 | none |
| all others | DJST |
| Security Profile | Requires mitigations |
|------------------|----------------------|
| FIXME | none |
| any | DJST |
#### 5.2.12.3 Mapping of mitigations to risk factors and security profiles
> FIXME: When full use case risk factor and tolerancesare available, update above table.
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.