Estimation Impact
Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.
Search
Last updated: 2026-06-25 12:57
RTRFQX Review TeamWorkspace
Estimation Impact
Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.
Requirements1789estimated
High Effort267drivers
Unknowns5need clarification
High Customer Dep.268blocked
High Risk385watch
Estimation Summary
| Impact Area | Low | Medium | High | Unknown | Notes |
|---|---|---|---|---|---|
| Effort | 741 | 554 | 267 | 5 | qualitative; no person-days |
| Competence | 789 | 848 | 152 | 0 | qualitative; no person-days |
| Tooling | 1024 | 636 | 129 | 0 | qualitative; no person-days |
| IT Infrastructure | 1301 | 0 | 488 | 0 | qualitative; no person-days |
| Hardware | 1625 | 78 | 86 | 0 | qualitative; no person-days |
| Test Environment | 1423 | 365 | 1 | 0 | qualitative; no person-days |
| Supplier Dependency | 1522 | 0 | 267 | 0 | qualitative; no person-days |
| Customer Dependency | 1131 | 390 | 268 | 0 | qualitative; no person-days |
| Risk | 794 | 610 | 385 | 0 | qualitative; no person-days |
Feature-Based Estimation View
| Feature / Capability | Requirement Count | Effort | Competence | Tooling | Customer Dependency |
|---|---|---|---|---|---|
| Diagnostic security | 24 | High | High | Medium | High |
| Cybersecurity requirement handling | 21 | Unknown | High | Medium | High |
| Authentication | 16 | High | High | High | High |
| Certificate handling | 16 | High | High | High | High |
| Key management | 14 | High | High | High | High |
| Vulnerability management | 2 | Medium | High | Medium | Medium |
| Incident response | 1 | Low | High | Low | Medium |
| Logging and audit trail | 1 | Low | High | Low | Medium |
| Secure communication | 1 | Medium | High | Low | High |
Document Traceability
Requirement-Based Estimation View
Show per-requirement estimation (1789)
| Requirement ID | Supplier Position | Effort | Tooling | IT/HW/Test | Reason | Recommended Action |
|---|---|---|---|---|---|---|
| RFQX-1001379436-P10-000-01-0001 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-1001379436-P10-000-01-0002 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-1001379436-P10-000-01-0003 | Needs Customer Clarification | Unknown | Medium | Low | Scope and effort cannot be frozen; estimation carries an open assumption and downstream design may rework. | Send linked open point to the customer for decision. |
| RFQX-1001379436-P10-000-01-0004 | Reference / Document Information | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No supplier action - document reference / boilerplate. |
| RFQX-1001379436-P10-000-01-0005 | Reference / Document Information | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | No supplier action - document reference / boilerplate. |
| RFQX-1001379436-P10-000-01-0006 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-1001379436-P10-000-01-0007 | Accept with Assumption | Medium | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0008 | Accept with Assumption | Medium | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0009 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0010 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0011 | Needs Customer Clarification | Unknown | Low | Low | Scope and effort cannot be frozen; estimation carries an open assumption and downstream design may rework. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0012 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0013 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0014 | Needs Customer Clarification | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0015 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0016 | Needs Customer Clarification | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0017 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0018 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0019 | Accept with Assumption | Low | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0020 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-1001379436-P10-000-01-0021 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0022 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0023 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-1001379436-P10-000-01-0024 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0025 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0026 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0027 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0028 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0029 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0030 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0031 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0032 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0033 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0034 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0035 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0036 | Partially Accept | Low | Low | Low | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-1001379436-P10-000-01-0037 | Accept with Assumption | Low | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0038 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-1001379436-P10-000-01-0039 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-1001379436-P10-000-01-0040 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-1001379436-P10-000-01-0041 | Partially Accept | High | High | Low | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-1001379436-P10-000-01-0042 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0043 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0044 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0045 | Accept with Assumption | High | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0046 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0047 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0048 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0049 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0050 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0051 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0052 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0053 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0054 | Partially Accept | Low | Low | Low | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-1001379436-P10-000-01-0055 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0056 | Needs Customer Clarification | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0057 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0058 | Accept with Assumption | Low | Low | High | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0059 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0060 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-1001379436-P10-000-01-0061 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-1001379436-P10-000-01-0062 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-1001379436-P10-000-01-0063 | Partially Accept | Low | Low | Low | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-1001379436-P10-000-01-0064 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0065 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0066 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-1001379436-P10-000-01-0067 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0001 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0002 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0003 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0004 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0005 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0006 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0007 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0008 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0009 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0010 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0011 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0012 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0013 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0014 | Accept | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0015 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0016 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0017 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0018 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0019 | Needs Internal Review | Low | Low | Low | Limited; standard implementation and verification risk. | Complete internal review of wording and baseline scope. |
| RFQX-3299216-1-0020 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0021 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0022 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0023 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0024 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0025 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0026 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0027 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0028 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0029 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0030 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0031 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0032 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0033 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0034 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0035 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0036 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0037 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0038 | Needs Customer Clarification | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0039 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0040 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0041 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0042 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0043 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0044 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0045 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0046 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0047 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0048 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0049 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0050 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0051 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0052 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0053 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0054 | Needs Customer Clarification | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0055 | Accept | Medium | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0056 | Needs Customer Clarification | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0057 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0058 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0059 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0060 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0061 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0062 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0063 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0064 | Needs Customer Clarification | High | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0065 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0066 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0067 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0068 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0069 | Needs Internal Review | Low | Low | Low | Limited; standard implementation and verification risk. | Complete internal review of wording and baseline scope. |
| RFQX-3299216-1-0070 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0071 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0072 | Needs Customer Clarification | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0073 | Needs Customer Clarification | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0074 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0075 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0076 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0077 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0078 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0079 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0080 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0081 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0082 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0083 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0084 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0085 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0086 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0087 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0088 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0089 | Accept with Assumption | High | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0090 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0091 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0092 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0093 | Needs Customer Clarification | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0094 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0095 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0096 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0097 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0098 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0099 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0100 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0101 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0102 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0103 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0104 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0105 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0106 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0107 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0108 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0109 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0110 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0111 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0112 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0113 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0114 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0115 | Accept with Assumption | Low | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0116 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0117 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0118 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0119 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0120 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0121 | Accept with Assumption | High | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0122 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0123 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0124 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0125 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0126 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0127 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0128 | Informational Only | Low | Low | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0129 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0130 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0131 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0132 | Needs Customer Clarification | High | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0134 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0135 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0136 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0137 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0138 | Accept | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0139 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0140 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0141 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0142 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0143 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0144 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0145 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0146 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0147 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0148 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0149 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0150 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0151 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0152 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0153 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0154 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0155 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0156 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0157 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0158 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0159 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0160 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0161 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0162 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0163 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0164 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0165 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0166 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0167 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0168 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0169 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0170 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0171 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0172 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0173 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0174 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0175 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0176 | Needs Customer Clarification | High | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0177 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0178 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0179 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0180 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0181 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-3299216-1-0182 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0183 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0184 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0185 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0186 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0187 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0188 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0189 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0190 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0191 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0192 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0193 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0194 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0195 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0196 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0197 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0198 | Accept | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0199 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0200 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0201 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0202 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0203 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0204 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0205 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0206 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0207 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0208 | Accept | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0209 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0210 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0211 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0212 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0213 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0214 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0215 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0216 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0217 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0218 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0219 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0220 | Needs Customer Clarification | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0221 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0222 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0223 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0224 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0225 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0226 | Informational Only | Low | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0227 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0228 | Accept with Assumption | Low | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0229 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0230 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0231 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0232 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0233 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0234 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0235 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0236 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0237 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0238 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0239 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0240 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0241 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0242 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0243 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0244 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0245 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-3299216-1-0246 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0247 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0248 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0249 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0250 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0251 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0252 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0253 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0254 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0255 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0256 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0257 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0258 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0259 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0260 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0261 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0262 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0263 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0264 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0265 | Informational Only | Low | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0266 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0267 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0268 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0269 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0270 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0271 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0272 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0273 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0274 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0275 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0276 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0277 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0278 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0279 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0280 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0281 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0282 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0283 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0284 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0285 | Accept with Assumption | Low | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-3299216-1-0286 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0287 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0288 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0289 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0290 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0291 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0292 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0293 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0294 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0295 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0296 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0297 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0298 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0299 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0300 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0301 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0302 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0303 | Needs Internal Review | Medium | Low | Low | Limited; standard implementation and verification risk. | Complete internal review of wording and baseline scope. |
| RFQX-3299216-1-0304 | Needs Internal Review | Low | Low | Low | Limited; standard implementation and verification risk. | Complete internal review of wording and baseline scope. |
| RFQX-3299216-1-0305 | Needs Internal Review | Low | Low | Low | Limited; standard implementation and verification risk. | Complete internal review of wording and baseline scope. |
| RFQX-3299216-1-0306 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-3299216-1-0307 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0308 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-3299216-1-0309 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0001 | Reference / Document Information | High | Low | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS123-2-0002 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0003 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0004 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0005 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0006 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0007 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0008 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0009 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0010 | Informational Only | None | Medium | High | Unverified security control could leave a residual risk in the cybersecurity case. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0011 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0012 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0013 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0014 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0015 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0016 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0017 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0018 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0019 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0020 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0021 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0022 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0023 | Needs Customer Clarification | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0024 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0025 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0026 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0027 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0028 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0029 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0030 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0031 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0032 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0033 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0034 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0035 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0036 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0037 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0038 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0039 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0040 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0041 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0042 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0043 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0044 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0045 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0046 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0047 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0048 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0049 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0050 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0051 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0052 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0053 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0054 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0055 | Needs Customer Clarification | High | Low | High | Scope and effort cannot be frozen; estimation carries an open assumption and downstream design may rework. | Send linked open point to the customer for decision. |
| RFQX-CVS123-2-0056 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0057 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0058 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0059 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0060 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0061 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0062 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0063 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0064 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0065 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0066 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0067 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0068 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0069 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0070 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0071 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0072 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0073 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0074 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0075 | Needs Customer Clarification | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0076 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0077 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0078 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0079 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0080 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0081 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0082 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0083 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0084 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0085 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0086 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0087 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0088 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0089 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0090 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0091 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0092 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0093 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0094 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0095 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0096 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0097 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0098 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0099 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0100 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0101 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0102 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0103 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0104 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0105 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0106 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0107 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0108 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0109 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0110 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0111 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0112 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0113 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0114 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0115 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0116 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0117 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0118 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0119 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0120 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0121 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0122 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0123 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0124 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0125 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0126 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0127 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0128 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0129 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0130 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0131 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0132 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0133 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0134 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0135 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0136 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0137 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0138 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0139 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0140 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0141 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0142 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0143 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0144 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0145 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0146 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0147 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0148 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0149 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0150 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0151 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0152 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0153 | Needs Customer Clarification | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0154 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0155 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0156 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0157 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0158 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0159 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0160 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0161 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0162 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0163 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0164 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0165 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0166 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0167 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0168 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0169 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0170 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0171 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0172 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0173 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0174 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0175 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0176 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0177 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0178 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0179 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0180 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0181 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0182 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0183 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0184 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0185 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0186 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0187 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0188 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0189 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0190 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0191 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0192 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0193 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0194 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0195 | Informational Only | Medium | Medium | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0196 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0197 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0198 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0199 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0200 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0201 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0202 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0203 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0204 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0205 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0206 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0207 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0208 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0209 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0210 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0211 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0212 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0213 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0214 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0215 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0216 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0217 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0218 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0219 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0220 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0221 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0222 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0223 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0224 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0225 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0226 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0227 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0228 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0229 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0230 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0231 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0232 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0233 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0234 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0235 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0236 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0237 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0238 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0239 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0240 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0241 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0242 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0243 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0244 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0245 | Informational Only | Medium | Medium | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0246 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0247 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0248 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0249 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0250 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0251 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0252 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0253 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0254 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0255 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0256 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0257 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0258 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0259 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0260 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0261 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0262 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0263 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0264 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0265 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0266 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0267 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0268 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0269 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0270 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0271 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0272 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0273 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0274 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0275 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0276 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0277 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0278 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0279 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0280 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0281 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0282 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0283 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0284 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0285 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0286 | Needs Customer Clarification | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0287 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0288 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0289 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0290 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0291 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0292 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0293 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0294 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0295 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0296 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0297 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0298 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0299 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0300 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0301 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0302 | Accept | Medium | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0303 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0304 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0305 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0306 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0307 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0308 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0309 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0310 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0311 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0312 | Informational Only | Medium | Medium | High | Unverified security control could leave a residual risk in the cybersecurity case. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0313 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0314 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0315 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0316 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0317 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0318 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0319 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0320 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0321 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0322 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0323 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0324 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0325 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0326 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0327 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0328 | Accept | Medium | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0329 | Accept | Medium | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0330 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0331 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0332 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0333 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS123-2-0334 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0335 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0336 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0337 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0338 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0339 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0340 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0341 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0342 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS123-2-0343 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0344 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0345 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0346 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0347 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0348 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS123-2-0349 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS123-2-0350 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS123-2-0351 | Needs Customer Clarification | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0001 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0002 | Reference / Document Information | Low | Low | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS124-0003 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0004 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0005 | Needs Customer Clarification | Unknown | Medium | High | Scope and effort cannot be frozen; estimation carries an open assumption and downstream design may rework. | Send linked open point to the customer for decision. |
| RFQX-CVS124-0006 | Reference / Document Information | High | Medium | High | Misinterpreted requirement could drive wrong design and late change cost. | No supplier action - document reference / boilerplate. |
| RFQX-CVS124-0007 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0008 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0009 | Needs Internal Review | Low | Low | Low | Limited; standard implementation and verification risk. | Complete internal review of wording and baseline scope. |
| RFQX-CVS124-0010 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0011 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0012 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0013 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0014 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0015 | Needs Internal Review | Low | Low | Low | Limited; standard implementation and verification risk. | Complete internal review of wording and baseline scope. |
| RFQX-CVS124-0016 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0017 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0018 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0019 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0020 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0021 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0022 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0023 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0024 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0025 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0026 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0027 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0028 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0029 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0030 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0031 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0032 | Informational Only | Medium | Medium | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0033 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0034 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0035 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0036 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0037 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0038 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0039 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0040 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0041 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0042 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0043 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0044 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0045 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0046 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0047 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0048 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0049 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0050 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0051 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0052 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0053 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0054 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0055 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0056 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0057 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0058 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0059 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0060 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0061 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0062 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0063 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0064 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0065 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0066 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0067 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0068 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0069 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0070 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0071 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0072 | Informational Only | High | High | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0073 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0074 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0075 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0076 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0077 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0078 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0079 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0080 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0081 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0082 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0083 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0084 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0085 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0086 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0087 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0088 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0089 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0090 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0091 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0092 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0093 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0094 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0095 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0096 | Informational Only | High | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0097 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0098 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0099 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0100 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0101 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0102 | Informational Only | High | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0103 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0104 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0105 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0106 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0107 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0108 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0109 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0110 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0111 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0112 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0113 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0114 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0115 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0116 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0117 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0118 | Informational Only | High | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0119 | Informational Only | High | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0120 | Informational Only | High | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0121 | Informational Only | High | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0122 | Informational Only | High | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0123 | Informational Only | High | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0124 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0125 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0126 | Informational Only | High | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0127 | Informational Only | High | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0128 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0129 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0130 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0131 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0132 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0133 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0134 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0135 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0136 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0137 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0138 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0139 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0140 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0141 | Needs Customer Clarification | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0142 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0143 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0144 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0145 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0146 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0147 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0148 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0149 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0150 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0151 | Informational Only | High | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0152 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0153 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0154 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0155 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0156 | Informational Only | High | High | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0157 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0158 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0159 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0160 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0161 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0162 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0163 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0164 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0165 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0166 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0167 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0168 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0169 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0170 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0171 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0172 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0173 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0174 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0175 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0176 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0177 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0178 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0179 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0180 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0181 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0182 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0183 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0184 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0185 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0186 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0187 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0188 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0189 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0190 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0191 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0192 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0193 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0194 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0195 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0196 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0197 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0198 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0199 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0200 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0201 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0202 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0203 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0204 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0205 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0206 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0207 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0208 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0209 | Accept with Assumption | Low | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0210 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0211 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0212 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0213 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0214 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0215 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0216 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0217 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0218 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0219 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0220 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0221 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0222 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0223 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0224 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0225 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0226 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0227 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0228 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0229 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0230 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0231 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0232 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0233 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0234 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0235 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0236 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0237 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0238 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0239 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0240 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0241 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0242 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0243 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0244 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0245 | Needs Customer Clarification | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0246 | Needs Customer Clarification | Unknown | Medium | Low | Scope and effort cannot be frozen; estimation carries an open assumption and downstream design may rework. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0247 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0248 | Needs Customer Clarification | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0249 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0250 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0251 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0252 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0253 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0254 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0255 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0256 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0257 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0258 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0259 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0260 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0261 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0262 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0263 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0264 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0265 | Needs Customer Clarification | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0266 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0267 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0268 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0269 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0270 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0271 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0272 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0273 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0274 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0275 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0276 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0277 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0278 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0279 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0280 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0281 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0282 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0283 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0284 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0285 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0286 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0287 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0288 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0289 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0290 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0291 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0292 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0293 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0294 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0295 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0296 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0297 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0298 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0299 | Informational Only | Low | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0300 | Accept with Assumption | Low | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0301 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0302 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0303 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0304 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0305 | Accept with Assumption | High | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0306 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0307 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0308 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0309 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0310 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0311 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0312 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0313 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0314 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0315 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0316 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0317 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0318 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0319 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0320 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0321 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0322 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0323 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0324 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0325 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0326 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0327 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0328 | Needs Customer Clarification | Low | Low | Low | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0329 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0330 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0331 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0332 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0333 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0334 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0335 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0336 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0337 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0338 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0339 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0340 | Needs Customer Clarification | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0341 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0342 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0343 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0344 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0345 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0346 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0347 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0348 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0349 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0350 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0351 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0352 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS124-0353 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0354 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0355 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0356 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0357 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0358 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0359 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0360 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0361 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0362 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0363 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0364 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0365 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0366 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0367 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0368 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0369 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0370 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0371 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0372 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0373 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0374 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0375 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0376 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0377 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0378 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0379 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0380 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0381 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0382 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS124-0383 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0384 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0385 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0386 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0387 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0388 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0389 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0390 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0391 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0392 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0393 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0394 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0395 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0396 | Informational Only | Medium | Medium | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0397 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0398 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0399 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0400 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0401 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0402 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0403 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0404 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0405 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0406 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0407 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0408 | Accept with Assumption | Low | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0409 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0410 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0411 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0412 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0413 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0414 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0415 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0416 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0417 | Accept with Assumption | Low | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0418 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0419 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0420 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0421 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0422 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0423 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0424 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0425 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0426 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0427 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0428 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0429 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0430 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0431 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0432 | Accept with Assumption | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0433 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0434 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0435 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0436 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0437 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS124-0438 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0439 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS124-0440 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0441 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0442 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0443 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0444 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0445 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0446 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0447 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0448 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0449 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0450 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0451 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0452 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0453 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0454 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0455 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0456 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0457 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0458 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0459 | Informational Only | High | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0460 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0461 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0462 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0463 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0464 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS124-0465 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0001 | Reference / Document Information | High | Medium | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS151-0002 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0003 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0004 | Needs Customer Clarification | High | Medium | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0005 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0006 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0007 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0008 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0009 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0010 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0011 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS151-0012 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0013 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0014 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0015 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0016 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0017 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0018 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0019 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0020 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0021 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0022 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0023 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0024 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0025 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0026 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0027 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0028 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0029 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0030 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0031 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0032 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0033 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0034 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0035 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0036 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0037 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0038 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0039 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0040 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0041 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0042 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0043 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0044 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0045 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0046 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0047 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0048 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0049 | Needs Customer Clarification | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0050 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0051 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS151-0052 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0053 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0054 | Needs Customer Clarification | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0055 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0056 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0057 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0058 | Needs Customer Clarification | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0059 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0060 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0061 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0062 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0063 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0064 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0065 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0066 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0067 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0068 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0069 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0070 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0071 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0072 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0073 | Reference / Document Information | Low | Low | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS151-0074 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0075 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0076 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0077 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0078 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS151-0079 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0080 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0081 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0082 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0083 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0084 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0085 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0086 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0087 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0088 | Partially Accept | Low | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS151-0089 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0090 | Informational Only | None | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS151-0091 | Needs Customer Clarification | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0092 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0093 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS151-0094 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS154-0001 | Reference / Document Information | Low | Low | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS154-0002 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS154-0003 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS154-0004 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS154-0005 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0006 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0007 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0008 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0009 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0010 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS154-0011 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0012 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0013 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS154-0014 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0015 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0016 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS154-0017 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0018 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0019 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0020 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0021 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS154-0022 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0023 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0024 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0025 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS154-0026 | Needs Customer Clarification | High | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS154-0027 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0028 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0029 | Accept | High | High | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0030 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0031 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0032 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS154-0033 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0034 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0035 | Needs Customer Clarification | Unknown | Low | High | Scope and effort cannot be frozen; estimation carries an open assumption and downstream design may rework. | Send linked open point to the customer for decision. |
| RFQX-CVS154-0036 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0037 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0038 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS154-0039 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0040 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0041 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0042 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0043 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0044 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS154-0045 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS154-0046 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS154-0047 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0001 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0002 | Reference / Document Information | Low | Low | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS31-0003 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0004 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0005 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0006 | Needs Customer Clarification | High | High | Low | Scope and effort cannot be frozen; estimation carries an open assumption and downstream design may rework. | Send linked open point to the customer for decision. |
| RFQX-CVS31-0007 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0008 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0009 | Needs Customer Clarification | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0010 | Needs Customer Clarification | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0011 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0012 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0013 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0014 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0015 | Needs Customer Clarification | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0016 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0017 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0018 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0019 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0020 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0021 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0022 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0023 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0024 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0025 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0026 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0027 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0028 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0029 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0030 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0031 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0032 | Informational Only | Medium | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0033 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0034 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0035 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0036 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0037 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0038 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0039 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0040 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0041 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0042 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0043 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0044 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0045 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0046 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0047 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0048 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0049 | Needs Customer Clarification | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0050 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0051 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0052 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0053 | Informational Only | Medium | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0054 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0055 | Informational Only | Medium | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0056 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0057 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0058 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0059 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0060 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0061 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0062 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0063 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0064 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0065 | Accept | Medium | Medium | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0066 | Accept with Assumption | High | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0067 | Partially Accept | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0068 | Accept | Medium | Medium | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0069 | Informational Only | Medium | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0070 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0071 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0072 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0073 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0074 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0075 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0076 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0077 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0078 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0079 | Informational Only | None | High | High | Unverified security control could leave a residual risk in the cybersecurity case. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0080 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0081 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0082 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0083 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0084 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0085 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0086 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0087 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0088 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0089 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0090 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0091 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0092 | Informational Only | High | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0093 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0094 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0095 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0096 | Needs Customer Clarification | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0097 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0098 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0099 | Needs Customer Clarification | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS31-0100 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0101 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0102 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0103 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0104 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0105 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0106 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0107 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0108 | Informational Only | Low | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0109 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0110 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0111 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0112 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0113 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0114 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0115 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0116 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0117 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0118 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0119 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0120 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0121 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0122 | Informational Only | High | High | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0123 | Informational Only | High | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0124 | Informational Only | High | High | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0125 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0126 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0127 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0128 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0129 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0130 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0131 | Informational Only | High | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0132 | Informational Only | High | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0133 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0134 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0135 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0136 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0137 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0138 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0139 | Informational Only | Medium | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0140 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0141 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0142 | Accept | Medium | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0143 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0144 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0145 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0146 | Accept with Assumption | High | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0147 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0148 | Accept | Low | Low | High | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0149 | Informational Only | None | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0150 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0151 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0152 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0153 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0154 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0155 | Accept | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm responsibility allocation, then implement and verify. |
| RFQX-CVS31-0156 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0157 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0158 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS31-0159 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0160 | Accept with Assumption | High | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS31-0161 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0162 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0163 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0164 | Informational Only | None | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0165 | Reference / Document Information | Low | Low | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS31-0166 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0167 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0168 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0169 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0170 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0171 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0172 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0173 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0174 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0175 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0176 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0177 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0178 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0179 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0180 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0181 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0182 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0183 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0184 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0185 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0186 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0187 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0188 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0189 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0190 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0191 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0192 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0193 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0194 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0195 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0196 | Informational Only | Medium | Medium | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0197 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0198 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0199 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0200 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0201 | Informational Only | High | High | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0202 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0203 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0204 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0205 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0206 | Informational Only | None | High | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0207 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0208 | Informational Only | High | High | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0209 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0210 | Informational Only | Low | Low | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0211 | Informational Only | High | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0212 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0213 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0214 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0215 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0216 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0217 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0218 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0219 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0220 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0221 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0222 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0223 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0224 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0225 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0226 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0227 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0228 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0229 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0230 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0231 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0232 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0233 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0234 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0235 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0236 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0237 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0238 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0239 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0240 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0241 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0242 | Informational Only | High | Low | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0243 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0244 | Informational Only | High | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0245 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0246 | Informational Only | High | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0247 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0248 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0249 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0250 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0251 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0252 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0253 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS31-0254 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0001 | Needs Customer Clarification | Low | Medium | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS32-0002 | Reference / Document Information | Low | Low | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS32-0003 | Needs Customer Clarification | Low | Low | Low | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS32-0004 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS32-0005 | Reference / Document Information | High | Medium | Low | Limited; standard implementation and verification risk. | No supplier action - document reference / boilerplate. |
| RFQX-CVS32-0006 | Informational Only | High | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0007 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0008 | Needs Customer Clarification | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS32-0009 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0010 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0011 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0012 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0013 | Informational Only | High | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0014 | Needs Customer Clarification | High | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS32-0015 | Informational Only | Medium | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0016 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0017 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0018 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0019 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0020 | Needs Customer Clarification | Low | Low | High | Limited; standard implementation and verification risk. | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| RFQX-CVS32-0021 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0022 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0023 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0024 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0025 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0026 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0027 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0028 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0029 | Accept with Assumption | High | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0030 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0031 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0032 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0033 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0034 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0035 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0036 | Informational Only | Medium | Low | High | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0037 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0038 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0039 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0040 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0041 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0042 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0043 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0044 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0045 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0046 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0047 | Accept with Assumption | Medium | Medium | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0048 | Partially Accept | Medium | Medium | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0049 | Informational Only | Medium | Medium | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0050 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0051 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0052 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0053 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0054 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0055 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0056 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0057 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0058 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0059 | Accept with Assumption | High | High | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0060 | Informational Only | Medium | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0061 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0062 | Informational Only | None | High | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0063 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0064 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0065 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0066 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0067 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0068 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0069 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0070 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0071 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0072 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0073 | Accept with Assumption | Low | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0074 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0075 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0076 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0077 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0078 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0079 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0080 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0081 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0082 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0083 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0084 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0085 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0086 | Informational Only | Medium | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0087 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0088 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0089 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0090 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0091 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0092 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0093 | Partially Accept | High | High | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0094 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0095 | Accept with Assumption | High | High | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0096 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0097 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0098 | Informational Only | Low | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0099 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0100 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0101 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0102 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0103 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0104 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0105 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0106 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0107 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0108 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0109 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0110 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0111 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0112 | Informational Only | Medium | High | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0113 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0114 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0115 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0116 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0117 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0118 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0119 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0120 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0121 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0122 | Partially Accept | Medium | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0123 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0124 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0125 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0126 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0127 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0128 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0129 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0130 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0131 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0132 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0133 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0134 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0135 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0136 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0137 | Informational Only | Medium | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0138 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0139 | Accept with Assumption | High | Low | Low | Unverified security control could leave a residual risk in the cybersecurity case. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0140 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0141 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0142 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0143 | Accept with Assumption | Medium | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0144 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0145 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0146 | Accept with Assumption | Low | Low | Low | Limited; standard implementation and verification risk. | Validate assumption with customer; complete mapping; implement. |
| RFQX-CVS32-0147 | Partially Accept | High | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0148 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0149 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0150 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0151 | Partially Accept | Low | Low | High | Responsibility gap between OEM and supplier could leave a security control unimplemented or duplicated. | Agree responsibility split (DIA) for the non-ECU portion. |
| RFQX-CVS32-0152 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0153 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0154 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0155 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0156 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0157 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0158 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0159 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0160 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0161 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0162 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0163 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0164 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0165 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0166 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0167 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0168 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0169 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0170 | Informational Only | Medium | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0171 | Informational Only | None | Low | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0172 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0173 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0174 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0175 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0176 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0177 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0178 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0179 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0180 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0181 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0182 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0183 | Informational Only | None | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0184 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0185 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0186 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0187 | Informational Only | None | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0188 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0189 | Informational Only | Low | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0190 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0191 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0192 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0193 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0194 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0195 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0196 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0197 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0198 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0199 | Informational Only | High | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0200 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0201 | Informational Only | Medium | Low | Low | Misinterpreted requirement could drive wrong design and late change cost. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0202 | Informational Only | High | Medium | High | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
| RFQX-CVS32-0203 | Informational Only | High | Low | Low | Limited; standard implementation and verification risk. | No action unless the customer confirms it is binding. |
Person-day figures are intentionally not generated (not configured).