@@ -1787,12 +1787,96 @@ The product shall have vulnerability handling processes compliant with <a ref="_
* Logging
* Monitoring/notifications
## C.2 Threats
> Based on the assets, what are the threats during:
>
> - Use for intended purpose or reasonably foreseeable use
> - When integrated into another product
## C.4 Threats
### C.4.1 General
The approach to listing threats is to separate them by mitigation so that they may be associated with mitigations more directly.
### C.4.2 Risk assessment methodology
Risk factor levels for each security profile are determined by reading the descriptions for each risk factor level and choosing the one that most accurately represents the highest risk for the intended purpose and reasonably foreseeable use and misuse of the product, as specified by the manufacturer.
For each threat, a formula based on the risk factor levels is used to calculate the Likelihood and Impact of the threat, on a scale of Low, Medium, and High.
For each threat, both likelihood and impact must be Low before the risk is considered sufficiently mitigated. If the calculated levels are not already Low, then mitigations must be applied until they are both Low. The mitigation sets that will accomplish this are listed in each threat description.