Security updates shall be timely. (12) (12) (12) (12) internal policies on ensuring the availability of security updates in a timely manner. Refer to supporting evidence requirements from ETSI 5.3-2 and 5-3-7. 5.3-9: RC The device should verify (12) the authenticity and integrity of software updates. 5.3-10: M Where updates are (11, delivered over a network 12) interface, the device shall verify the authenticity and integrity of each update via a trust relationship. 5.3-11: RC The manufacturer should (12) inform the user in a recognizable and apparent manner that a security update is required together with information on the risks mitigated by that update. 5.3-12: RC The device should notify (12) the user when the application of a software update will disrupt the basic functioning of the device. RC (12) RC (12) RC (12) M (11, 12) M (11, 12) M (11, 12) RC (12) RC (12) RC (12) Supporting evidence shall describe the notification mechanism(s) in which the user is informed of a security update. RC (12) RC (12) RC (12) Supporting evidence shall show how the user is informed of a software update that will disrupt the basic functioning of the device. CLS Publication #2 | Page 30 of 49

Select target paragraph3