GM5 Article 15(1)(b) Conditions for
obtaining a certificate
ED Decision
2022/022/R
The security risk assessment may cover the following steps and security items:
(a) determination of the operational environment of the functional system;
(b) identification of the digital interfaces and assets (i.e. the items contributing to, or sustaining, cybersecurity);
(c) identification of the attack paths;
(d) considering the usual attack (e.g. DoS), assessment of the consequences and severity of the identified threat on the affected items;
(e) evaluation of the potentiality of a successful exploit, or of the difficulty of performing a successful attack that would have an impact on the typical security attributes: confidentiality, availability, integrity;
(f) an iterative approach to converge on an acceptable level of residual risk:
(1) evaluate the severities in conjunction with the potential for attack (or, inversely, the difficulty of attacking);
(2) the outcome of the evaluation is acceptable and does not need additional or strengthened mitigation means;
(3) the outcome of the evaluation is not acceptable and requires an analysis to identify mitigation means to reach an acceptable level of safety;
(4) evaluation of the effectiveness of the mitigation means with respect to the level of risk (combination of the level of threat and severity of the threat condition).
Loading collections...