@@ -1738,7 +1738,7 @@ The product shall protect the availability of essential and core network service
The product shall be securely updateable by the user.
> FIXME: Waiting on legal approval to include self-update text, following text is for update by the operational environment (other OS, human process, etc.)
> TODO: Waiting on completion of ETSI membership process to include detailed secure update text from an ETSI delegate. The following text is for update by the operational environment (other OS, human process, etc.).
#### 5.2.X.x **MI-SCHL**: Low security updates provided by operational environment
@@ -1772,15 +1772,7 @@ The technical documentation provided with the product shall document that the op
#### 5.2.X.x Mapping of mitigations to risk factors and security profiles
| Risk factors | Requires mitigations |
|--------------|----------------------|
| RT-High | SCDL |
| RT-Medium | SCDM |
| RT-Low | SCDH |
> FIXME: When full use case risk factor and tolerances are available, update above table.
> FIXME: When self update requirements are available, update above table.
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.