@@ -548,7 +548,7 @@ _The following use cases are provided to assist manufacturers in selecting risk
* does not have accessible I/O ports
* hardware likely contains tamper-evident signals which operating system can rely on
***UC-MOB-1** A adult's personal mobile device
***UC-MOB-1** A personal mobile device
* stores highly sensitive personal information
* large number of sensors allow mass collection of sensitive personal data
* size and cost make it a common target of theft
@@ -559,10 +559,6 @@ _The following use cases are provided to assist manufacturers in selecting risk
* device frequently collects user's location at all times
* device is often always on and always connected
***UC-MOB-2** A children's mobile device
* may have multiple users
* TBD
***UC-WE-1** A wearable health tracker, such as a smart watch
* stores information about a single user only
* stored information may be highly sensitive, and is likely to be strictly structured (not arbitrary files)
@@ -1673,12 +1669,6 @@ The technical documentation provided with the product shall document that the op
> List any related ETSI standards and how they interact with the present document.
## B.1 Mobile Devices
The ETSI TS 103 732 series, derived from EN 303 645 and targeted to consumer mobile devices may be used to show compliance to the requirements in the present document.
> Should there be a mapping to show the relationship? Should that be to the threats, the risks, the mitigations?
# Annex C (informative): Risk identification and assessment methodology
## C.1 Assets
@@ -2029,7 +2019,7 @@ Description: A business-grade remote door locking system
* Mobile devices generally come with the operating system pre-installed and unable to be changed to different operating system
* The operating system is generally locked down such that the user does not have access to deep control or actual administrator rights, they are limited to controls focused on user interactivity while maintaining the lower functions restricted
* While there are settings for the user to adjust, these are rarely in how the operating system itself functions, but focused on interactions at the user level
* As a child's device, it may be carried a lot, but is more likely to be overseen by a parent, making it less likely to be stolen
* As a child's device, it is less likely to carry as much sensitive information, as the users are not accessing sensitive services
* The child's device may have multiple accounts for different family members, or a primary account for the parents to manage the device and other accounts for the child
* Network risk is high due to the use on untrusted networks
* Derived Risk Tolerance: LOW (2) or MEDIUM (3)
#### C.7.2.7 SP-WE-1 :: RT-????
Description: A wearable health tracker, such as a smart watch