145
rIsk AssessMent teChnIques
• e device components, communications architectures, and
processing capabilities must be known.
• e designed function, including all positive and negative
logic states, must be understood.
• Communications protocols and device communication design
must be documented and understood with all legitimate per-
mutations exercised.
• Exception handling (fail-safe) protocols and functionality
must be tested in a suitable set of permutations.
e SAL model requires additional considerations when testing
devices for specic security resiliency and protection against security
violations. For instance:
• Device stack management—Following good design patterns,
unit testing, system testing, avoiding deprecated libraries ...