@@ -1680,6 +1680,23 @@ If the product provides a method to transfer data and settings to another produc
See Section 5.3 for which mitigations are necessary for which security profiles and Annex C.4 for the rationale.
### 5.2.18 TR-VULH: Vulnerability handling
#### 5.2.18.1 Requirement
The product shall have vulnerability handling processes compliant with <aref="_ref_3">[3] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Vulnerability Handling".
#### 5.2.18.2 MI-VULH: Vulnerability handling
The product shall have vulnerability handling processes compliant with <aref="_ref_3">[3] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Vulnerability Handling".
* Applicability: (for requirements that depend on a feature)
* Reference: TR-VULH
* Objective: Vulnerability handling
* Activities: Review documentation associated with vulnerability handling.
* Verdict: Vulnerability handling documentation is compliant with <aref="_ref_3">[3] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Vulnerability Handling" => PASS, otherwise FAIL
* Evidence: Vulnerability handling documentation, comparison with <aref="_ref_3">[3] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Vulnerability Handling"
## 5.3 Risk Mitigation Sets
> TODO: Connect the technical security requirements in clause 5.2 to specific Risk Factors, and define these as sets of Risk Mitigations that will be referenced in clause 6.
@@ -1708,6 +1725,7 @@ See Section 5.3 for which mitigations are necessary for which security profiles