Commit a87f4b1a authored by Valerie Aurora (Bow Shock)'s avatar Valerie Aurora (Bow Shock)
Browse files

Rewrite CONF risk formula

parent 5114b0ff
Loading
Loading
Loading
Loading
+11 −11
Original line number Diff line number Diff line
@@ -1858,16 +1858,16 @@ Mitigations for Impact:
Attacker may use configuration errors to get unauthorized access to the product assets.

| Risk factors         | Likelihood | Security profiles               |
|---------------------------------------------------------|------------|----------------------------------------|
| CONF = 0 or max(NUSR, CUSR, PHYS, TNET, FNET, ADMN) = 0 | Low        | LR, IoT-1, WE-1                        |
| all others                                              | Medium     | IoT-2, IoT-3, OT-1                     |
| CONF = 2 & max(NUSR, CUSR, PHYS, TNET, FNET, ADMN) = 2  | High       | RO-1, MOB-1, PC-\*, LA-\*, PS-1, SE-\* |
|----------------------|------------|---------------------------------|
| CONF = 0 or DATA = 0 | Low        | LR, IoT-1, WE-1                 |
| all others           | Medium     | IoT-2, IoT-3, OT-1, PS-1, SE-\* |
| CONF = 2 & DATA = 2  | High       | MOB-1, PC-\*, LA-\*             |

| Risk factors              | Impact | Security profiles                                         |
|---------------------------------|--------|-----------------------------------------------------------|
| max(PPII, SNDS, SNDT, SENF) = 0 | Low    | LR, IoT-1                                                 |
| max(PPII, SNDS, SNDT, SENF) = 1 | Medium | IoT-2, IoT-3                                              |
| max(PPII, SNDS, SNDT, SENF) = 2 | High   | IoT-3, RO-1, OT-1, MOB-1, WE-1, PC-\*, LA-\*, PS-1, SE-\* |
|---------------------------|--------|-----------------------------------------------------------|
| max(SNDS, SNDT, SENF) = 0 | Low    | LR, IoT-1                                                 |
| max(SNDS, SNDT, SENF) = 1 | Medium | IoT-2, IoT-3                                              |
| max(SNDS, SNDT, SENF) = 2 | High   | IoT-3, RO-1, OT-1, MOB-1, WE-1, PC-\*, LA-\*, PS-1, SE-\* |

Requirements that mitigate this threat: CDST, SDEF, DMIN, LOGG