<?xml version="1.0" encoding="UTF-8"?><toc><section id="sec_foreword"><title>Foreword</title></section><section id="sec_intro"><title>Introduction</title></section><section id="sec_1"><label>1</label><title>Scope</title></section><section id="sec_2"><label>2</label><title>Normative references</title></section><section id="sec_3"><label>3</label><title>Terms and definitions</title></section><section id="sec_4"><label>4</label><title>Field of application</title><section id="sec_4.1"><label>4.1</label><title>Statement of application</title></section><section id="sec_4.2"><label>4.2</label><title>Business partners</title></section><section id="sec_4.3"><label>4.3</label><title>Internationally accepted certificates or approvals</title></section><section id="sec_4.4"><label>4.4</label><title>Business partners exempt from security declaration requirement</title></section><section id="sec_4.5"><label>4.5</label><title>Security reviews of business partners</title></section></section><section id="sec_5"><label>5</label><title>Supply chain security process</title><section id="sec_5.1"><label>5.1</label><title>General</title></section><section id="sec_5.2"><label>5.2</label><title>Identification of the scope of the security assessment</title></section><section id="sec_5.3"><label>5.3</label><title>Conduction of the security assessment</title><section id="sec_5.3.1"><label>5.3.1</label><title>Assessment personnel</title></section><section id="sec_5.3.2"><label>5.3.2</label><title>Assessment process</title></section></section><section id="sec_5.4"><label>5.4</label><title>Development of the supply chain security plan</title></section><section id="sec_5.5"><label>5.5</label><title>Execution of the supply chain security plan</title></section><section id="sec_5.6"><label>5.6</label><title>Documentation and monitoring of the supply chain security process</title><section id="sec_5.6.1"><label>5.6.1</label><title>General</title></section><section id="sec_5.6.2"><label>5.6.2</label><title>Continual improvement</title></section></section><section id="sec_5.7"><label>5.7</label><title>Actions required after a security incident</title></section><section id="sec_5.8"><label>5.8</label><title>Protection of the security information</title></section></section><section id="sec_A"><label>Annex A</label><title>Supply chain security process (informative)</title><section id="sec_A.1"><label>A.1</label><title>General</title></section><section id="sec_A.2"><label>A.2</label><title>Identification of the scope of the security assessment</title></section><section id="sec_A.3"><label>A.3</label><title>Conduction of the security assessment</title><section id="sec_A.3.1"><label>A.3.1</label><title>General</title></section><section id="sec_A.3.2"><label>A.3.2</label><title>Performance review list</title></section><section id="sec_A.3.3"><label>A.3.3</label><title>Performance review</title></section><section id="sec_A.3.4"><label>A.3.4</label><title>Security threat scenarios</title></section></section><section id="sec_A.4"><label>A.4</label><title>Development of the security plan</title><section id="sec_A.4.1"><label>A.4.1</label><title>General</title></section><section id="sec_A.4.2"><label>A.4.2</label><title>Documentation</title></section><section id="sec_A.4.3"><label>A.4.3</label><title>Communication</title></section></section><section id="sec_A.5"><label>A.5</label><title>Execution of the security plan</title></section><section id="sec_A.6"><label>A.6</label><title>Documentation and monitoring of the security process</title></section><section id="sec_A.7"><label>A.7</label><title>Continual improvement</title></section></section><section id="sec_B"><label>Annex B</label><title>Methodology for security risk assessment and development of countermeasures (informative)</title><section id="sec_B.1"><label>B.1</label><title>General</title></section><section id="sec_B.2"><label>B.2</label><title>Step one – Consideration of the security threat scenarios</title></section><section id="sec_B.3"><label>B.3</label><title>Step two – Classification of consequences</title></section><section id="sec_B.4"><label>B.4</label><title>Step three – Classification of likelihood of security incidents</title></section><section id="sec_B.5"><label>B.5</label><title>Step four – Security incident scoring</title></section><section id="sec_B.6"><label>B.6</label><title>Step five – Development of countermeasures</title></section><section id="sec_B.7"><label>B.7</label><title>Step six – Implementation of countermeasures</title></section><section id="sec_B.8"><label>B.8</label><title>Step seven – Evaluation of countermeasures</title></section><section id="sec_B.9"><label>B.9</label><title>Step eight – Repetition of the process</title></section><section id="sec_B.10"><label>B.10</label><title>Continuation of the process</title></section></section><section id="sec_C"><label>Annex C</label><title>Guidance for obtaining advice and certification (informative)</title><section id="sec_C.1"><label>C.1</label><title>General</title></section><section id="sec_C.2"><label>C.2</label><title>Demonstrating conformance with  by audit</title></section><section id="sec_C.3"><label>C.3</label><title>Certification of  by third party certification bodies</title></section></section><section id="sec_bibl"><title>Bibliography</title></section></toc>