Annex C — Interaction of risk management concepts and activities
Annex C (informative) explains how clauses, concepts, and activities in FprEN 40000-1-2 interact with each other and with related standards in the EN 40000 series.
What Annex C requires
Annex C illustrates two critical structural relationships:
1. Cyclic clause relationships (Figure C.1)
Risk management is a continuous cycle. Risk review (6.7) and monitoring (7.8) feed back into product context (6.2), threat assessments (6.4), updated security requirements (7.3), and architectural redesign (7.4).
2. Conceptual traceability model (Figure C.2)
Based on ISO/SAE 21434, Annex C details logical connections between technical elements:
- Products operate in operational environments and consist of components.
- Assets carry specific cybersecurity properties (confidentiality, integrity, availability).
- Cybersecurity objectives protect assets against threats.
- Realized threats lead to consequences affecting end users.
- Cybersecurity risks derive from threat likelihood and impact severity.
- Cybersecurity requirements are allocated to products and components to mitigate risks.
How CVD Portal supports compliance
CVD Portal provides complete conceptual traceability across your entire security posture:
- End-to-end data linkage: In CVD Portal, a reported vulnerability links directly to affected SBOM components, exposed assets, CVSS risk scores, active controls, and resulting CSAF advisories.
- Dynamic feedback loops: Incoming vulnerability reports automatically trigger risk reviews, update control readiness scores, and log entries in the audit trail.
- Audit-ready traceability matrix: Exported technical files include full traceability reports connecting assets, threats, requirements, verification tests, and remediation evidence for external auditors.