• • • result of SAST test or internal document(s) describing the process of SAST. Dynamic analysis security testing (DAST): tool report describing the result of DAST test or internal document(s) describing the process of DAST. Application programming interfaces (API) testing: tool report describes the result of API test or internal document(s) describing the process of API testing. Fuzz testing: tool report describing the result of fuzzing or internal document(s) describing the process of fuzz testing. Indicate the tools used to conduct the above test and state other integrated security related activities conducted (if any). CK-LP-03 Do you implement and maintain the device with components from a secure supply chain, with no known unmitigated vulnerabilities? - M M M Provide internal document(s) showing the following measures are conducted to ensure the device components have no known unmitigated vulnerabilities: • Patching all vulnerable third-party libraries that are used (e.g. OpenSSL, underlying Linux etc) CLS Publication #2 | Page 46 of 49

Select target paragraph3