| Identification & Assessment of Risks
(Asset-Threat-Vulnerability) |
| Asset ID | Asset Description | Asset Value | Vulnerability Description | V code | V-ID | A/V-ID | A/V Value | Threats | T code | T-ID | Threat Value | A/V/T ID | Risk Value | Risk Value
(Final) |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A1V1 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A1.V1.T6 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A1V1 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V1.T8 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A1V1 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V1.T11 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A1V1 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V1.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A1V1 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A1.V1.T13 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A1V1 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V1.T14 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A1V1 | 3 | T27. Trade union/labor strikes | T27 | T27 | 3 | A1.V1.T27 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A1V10 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A1.V10.T1 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A1V10 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V10.T11 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A1V10 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V10.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A1V10 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A1.V10.T22 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A1V10 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A1.V10.T25 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A1V10 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A1.V10.T28 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A1.V12.T9 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V12.T10 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V12.T11 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V12.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V12.T30 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A1.V12.T9 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V12.T10 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V12.T11 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V12.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V12.T30 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A1V12 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A1.V12.T13 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A1.V14.T2 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A1.V14.T3 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A1.V14.T5 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A1.V14.T6 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V14.T8 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A1.V14.T9 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A1.V14.T7 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V14.T10 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V14.T11 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V14.T12 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V14.T14 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A1.V14.T16 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A1.V14.T22 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A1.V14.T23 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A1V14 | 4 | T27. Trade union/labor strikes | T27 | T27 | 3 | A1.V14.T27 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V15. Insufficient equipment | V15 | V15 | A1V15 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V15.T11 | 6 | 6 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V15. Insufficient equipment | V15 | V15 | A1V15 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V15.T30 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V16. Inappropriate expansion of the trust perimeter | V16 | V16 | A1V16 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V16.T8 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V16. Inappropriate expansion of the trust perimeter | V16 | V16 | A1V16 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V16.T14 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V16. Inappropriate expansion of the trust perimeter | V16 | V16 | A1V16 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A1.V16.T6 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A1V18 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A1.V18.T3 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A1V18 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V18.T12 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A1V18 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A1.V18.T13 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A1V18 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A1.V18.T26 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A1V18 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V18.T30 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A1V19 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A1.V19.T2 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A1V19 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A1.V19.T3 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A1V19 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A1.V19.T6 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A1V19 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V19.T8 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A1V19 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V19.T12 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A1V19 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A1.V19.T13 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A1V19 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A1.V19.T26 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A1V2 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A1.V2.T1 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A1V2 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A1.V2.T2 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A1V2 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A1.V2.T5 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A1V2 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A1.V2.T22 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A1V2 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A1.V2.T24 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A1V2 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A1.V2.T25 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A1V2 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A1.V2.T28 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A1V20 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A1.V20.T3 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A1V20 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V20.T11 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A1V20 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V20.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A1V20 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A1.V20.T13 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A1V20 | 3 | T26. State surveillance on citizens | T26 | T26 | 5 | A1.V20.T26 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A1V20 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V20.T30 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A1V21 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A1.V21.T2 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A1V21 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A1.V21.T5 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A1V21 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A1.V21.T6 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A1V21 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V21.T8 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A1V21 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V21.T14 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A1V28 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V28.T8 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A1V28 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V28.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A1V3 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A1.V3.T1 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A1V3 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A1.V3.T6 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A1V3 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A1.V3.T7 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A1V3 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A1.V3.T9 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A1V3 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A1.V3.T22 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A1V3 | 4 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A1.V3.T23 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A1V3 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A1.V3.T25 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A1V3 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A1.V3.T28 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A1V36 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V36.T10 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A1V36 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V36.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A1V36 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A1.V36.T23 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A1V36 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V36.T30 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V37. Failure of biometrics sensors | V37 | V37 | A1V37 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A1.V37.T2 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V37. Failure of biometrics sensors | V37 | V37 | A1V37 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V37.T8 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V37. Failure of biometrics sensors | V37 | V37 | A1V37 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V37.T10 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V37. Failure of biometrics sensors | V37 | V37 | A1V37 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V37.T14 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A1V38 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V38.T10 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A1V38 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V38.T11 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A1V38 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V38.T12 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A1V38 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A1.V38.T13 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A1V38 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V38.T30 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A1.V4.T2 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A1.V4.T6 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A1.V4.T7 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V4.T8 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A1.V4.T9 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V4.T10 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V4.T11 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V4.T12 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A1.V4.T13 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V4.T14 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A1.V4.T16 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A1.V4.T22 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A1V4 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V4.T30 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A1.V39.T1 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A1.V39.T4 | 6 | 6 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V39.T8 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V39.T10 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V39.T12 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T19. Jamming | T19 | T19 | 2 | A1.V39.T19 | 5 | 5 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A1.V39.T20 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A1.V39.T24 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A1.V39.T29 | 5 | 5 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A1V39 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A1.V39.T2 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A1V5 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V5.T8 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A1V5 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A1.V5.T9 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A1V5 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V5.T10 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A1V5 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V5.T11 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A1V5 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V5.T14 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A1V5 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V5.T30 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A1V6 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A1.V6.T9 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A1V6 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A1.V6.T22 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A1V6 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V6.T11 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A1V6 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V6.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A1V6 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A1.V6.T30 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A1V7 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V7.T10 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A1V7 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V7.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A1V7 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A1.V7.T11 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A1V7 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V7.T14 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A1V7 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A1.V7.T23 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V8. Dependency on power systems | V8. | V8 | A1V8 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A1.V8.T1 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V8. Dependency on power systems | V8. | V8 | A1V8 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A1.V8.T22 | 10 | 10 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V8. Dependency on power systems | V8. | V8 | A1V8 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A1.V8.T25 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A1.V9.T2 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A1.V9.T3 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A1.V9.T5 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A1.V9.T6 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A1.V9.T7 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A1.V9.T8 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A1.V9.T9 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A1.V9.T10 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A1.V9.T14 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A1.V9.T15 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T17. Side channel attack | T17 | T17 | 2 | A1.V9.T17 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T18. Blocking | T18 | T18 | 2 | A1.V9.T18 | 7 | 7 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T19. Jamming | T19 | T19 | 2 | A1.V9.T19 | 6 | 6 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A1.V9.T20 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A1.V9.T21 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A1.V9.T24 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A1V9 | 3 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A1.V9.T29 | 6 | 6 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A1V20 | 3 | T31. Data linkability | T31 | T31 | 4 | A1.V20.T31 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A1V21 | 3 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A1.V21.T33 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A1V38 | 4 | T32. Profiling | T32 | T32 | 4 | A1.V38.T32 | 9 | 9 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V41. Lack of respect to the data conservation principle | V41 | V41 | A1V41 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V41.T12 | 8 | 8 |
| A1 | Automated reservation, check-in and boarding procedure | 4 | V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). | V42 | V42 | A1V42 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A1.V42.T12 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A10.V21.T1 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A10.V21.T2 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A10.V21.T4 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A10.V21.T5 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A10.V21.T15 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T17. Side channel attack | T17 | T17 | 2 | A10.V21.T17 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T18. Blocking | T18 | T18 | 2 | A10.V21.T18 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T19. Jamming | T19 | T19 | 2 | A10.V21.T19 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A10.V21.T20 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A10.V21.T21 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A10.V21.T1 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A10.V21.T2 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A10.V21.T4 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A10.V21.T5 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A10.V21.T15 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T17. Side channel attack | T17 | T17 | 2 | A10.V21.T17 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T18. Blocking | T18 | T18 | 2 | A10.V21.T18 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T19. Jamming | T19 | T19 | 2 | A10.V21.T19 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A10.V21.T20 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A10.V21.T21 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A10.V21.T22 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A10.V24.T2 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A10.V24.T6 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A10.V24.T7 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A10.V24.T8 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A10.V24.T9 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A10.V24.T10 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A10.V24.T11 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A10.V24.T12 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A10.V24.T13 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A10V24 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A10.V24.T14 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A10V6 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A10.V6.T9 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A10V6 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A10.V6.T22 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A10V6 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A10.V6.T11 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A10V6 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A10.V6.T12 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A10V6 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A10.V6.T30 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A10.V31.T2 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A10.V31.T3 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A10.V31.T5 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A10.V31.T6 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A10.V31.T7 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A10.V31.T8 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A10.V31.T9 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A10.V31.T10 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A10.V31.T14 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A10.V31.T15 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T17. Side channel attack | T17 | T17 | 2 | A10.V31.T17 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T18. Blocking | T18 | T18 | 2 | A10.V31.T18 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T19. Jamming | T19 | T19 | 2 | A10.V31.T19 | 6 | 6 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A10.V31.T20 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A10.V31.T21 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A10.V31.T24 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A10.V31.T29 | 6 | 6 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A10.V31.T20 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A10V31 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A10.V31.T24 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A10.V13.T1 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A10.V13.T2 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A10.V13.T4 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A10.V13.T5 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A10.V13.T15 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T17. Side channel attack | T17 | T17 | 2 | A10.V13.T17 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T18. Blocking | T18 | T18 | 2 | A10.V13.T18 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T19. Jamming | T19 | T19 | 2 | A10.V13.T19 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A10.V13.T20 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A10.V13.T21 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A10V13 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A10.V13.T22 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A10.V12.T9 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A10.V12.T10 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A10.V12.T11 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A10.V12.T12 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A10.V12.T30 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A10.V12.T9 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A10.V12.T10 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A10.V12.T11 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A10.V12.T12 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A10.V12.T30 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A10V12 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A10.V12.T13 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A10V18 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A10.V18.T30 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A10.V21.T2 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A10.V21.T5 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A10.V21.T6 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A10.V21.T8 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A10V21 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A10.V21.T14 | 10 | 10 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V22. Collision of tag traffic / Radio-frequency interference | V22 | V22 | A10V22 | 2 | T18. Blocking | T18 | T18 | 2 | A10.V22.T18 | 6 | 6 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V22. Collision of tag traffic / Radio-frequency interference | V22 | V22 | A10V22 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A10.V22.T13 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A10V38 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A10.V38.T10 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A10V38 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A10.V38.T11 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A10V38 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A10.V38.T12 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A10V38 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A10.V38.T13 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A10V38 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A10.V38.T30 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A10.V39.T1 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A10.V39.T4 | 8 | 8 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A10.V39.T8 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A10.V39.T10 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A10.V39.T12 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T19. Jamming | T19 | T19 | 2 | A10.V39.T19 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A10.V39.T20 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A10.V39.T24 | 9 | 9 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A10.V39.T29 | 7 | 7 |
| A10 | Credit Cards/Debit card/Payment cards/'e-wallet' | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A10V39 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A10.V39.T2 | 10 | 10 |
| A11 | Other RFID cards | 3 | V21. Inappropriate / inadequate identity management | V21 | V21 | A11V21 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A11.V21.T1 | 8 | 8 |
| A11 | Other RFID cards | 3 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A11V4 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A11.V4.T13 | 8 | 8 |
| A11 | Other RFID cards | 3 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A11V4 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A11.V4.T14 | 8 | 8 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A11.V24.T2 | 8 | 8 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A11.V24.T6 | 7 | 7 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A11.V24.T7 | 7 | 7 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A11.V24.T8 | 7 | 7 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A11.V24.T9 | 6 | 6 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A11.V24.T14 | 8 | 8 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A11.V24.T15 | 7 | 7 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A11.V24.T16 | 7 | 7 |
| A11 | Other RFID cards | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A11V24 | 3 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A11.V24.T21 | 8 | 8 |
| A11 | Other RFID cards | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A11V6 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A11.V6.T9 | 6 | 6 |
| A11 | Other RFID cards | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A11V6 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A11.V6.T22 | 8 | 8 |
| A11 | Other RFID cards | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A11V6 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A11.V6.T11 | 6 | 6 |
| A11 | Other RFID cards | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A11V6 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A11.V6.T12 | 7 | 7 |
| A11 | Other RFID cards | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A11V6 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A11.V6.T30 | 7 | 7 |
| A11 | Other RFID cards | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A11V9 | 2 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A11.V9.T24 | 6 | 6 |
| A11 | Other RFID cards | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A11V9 | 2 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A11.V9.T29 | 4 | 4 |
| A11 | Other RFID cards | 3 | V25. Actual RFID range longer than standard | V25 | V25 | A11V25 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A11.V25.T8 | 8 | 8 |
| A11 | Other RFID cards | 3 | V25. Actual RFID range longer than standard | V25 | V25 | A11V25 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A11.V25.T5 | 8 | 8 |
| A11 | Other RFID cards | 3 | V25. Actual RFID range longer than standard | V25 | V25 | A11V25 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A11.V25.T20 | 8 | 8 |
| A11 | Other RFID cards | 3 | V26. RFID tags do not have a turn-off option | V26 | V26 | A11V26 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A11.V26.T20 | 7 | 7 |
| A11 | Other RFID cards | 3 | V27. Insufficient protection against reverse engineering | V27 | V27 | A11V27 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A11.V27.T15 | 7 | 7 |
| A11 | Other RFID cards | 3 | V27. Insufficient protection against reverse engineering | V27 | V27 | A11V27 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A11.V27.T20 | 7 | 7 |
| A11 | Other RFID cards | 3 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A11V28 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A11.V28.T8 | 8 | 8 |
| A11 | Other RFID cards | 3 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A11V28 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A11.V28.T12 | 8 | 8 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A11.V31.T4 | 6 | 6 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A11.V31.T5 | 7 | 7 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A11.V31.T6 | 7 | 7 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A11.V31.T7 | 7 | 7 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A11.V31.T8 | 7 | 7 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A11.V31.T10 | 7 | 7 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A11.V31.T15 | 7 | 7 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A11.V31.T20 | 7 | 7 |
| A11 | Other RFID cards | 3 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A11V31 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A11.V31.T24 | 7 | 7 |
| A11 | Other RFID cards | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A11V12 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A11.V12.T9 | 6 | 6 |
| A11 | Other RFID cards | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A11V12 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A11.V12.T10 | 7 | 7 |
| A11 | Other RFID cards | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A11V12 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A11.V12.T11 | 6 | 6 |
| A11 | Other RFID cards | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A11V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A11.V12.T12 | 7 | 7 |
| A11 | Other RFID cards | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A11V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A11.V12.T30 | 7 | 7 |
| A11 | Other RFID cards | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A11V12 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A11.V12.T13 | 8 | 8 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A11.V38.T3 | 7 | 7 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A11.V38.T12 | 7 | 7 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A11.V38.T13 | 8 | 8 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T26. State surveillance on citizens | T26 | T26 | 5 | A11.V38.T26 | 8 | 8 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A11.V38.T10 | 7 | 7 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A11.V38.T11 | 6 | 6 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A11.V38.T12 | 7 | 7 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A11.V38.T13 | 8 | 8 |
| A11 | Other RFID cards | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A11V38 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A11.V38.T30 | 7 | 7 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A11.V39.T1 | 7 | 7 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A11.V39.T4 | 6 | 6 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A11.V39.T8 | 7 | 7 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A11.V39.T10 | 7 | 7 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A11.V39.T12 | 7 | 7 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T19. Jamming | T19 | T19 | 2 | A11.V39.T19 | 5 | 5 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A11.V39.T20 | 7 | 7 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A11.V39.T24 | 7 | 7 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A11.V39.T29 | 5 | 5 |
| A11 | Other RFID cards | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A11V39 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A11.V39.T2 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A12V1 | 2 | T6. Social engineering attack | T6. | T6 | 4 | A12.V1.T6 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A12V1 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A12.V1.T8 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A12V1 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A12.V1.T11 | 5 | 5 |
| A12 | Scanners & detectors | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A12V1 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A12.V1.T12 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A12V1 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A12.V1.T13 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A12V1 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A12.V1.T14 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A12V1 | 2 | T27. Trade union/labor strikes | T27 | T27 | 3 | A12.V1.T27 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A12.V11.T1 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A12.V11.T2 | 9 | 9 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A12.V11.T5 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A12.V11.T22 | 9 | 9 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A12.V11.T24 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A12.V11.T25 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A12.V11.T28 | 9 | 9 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A12.V11.T12 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A12.V11.T14 | 9 | 9 |
| A12 | Scanners & detectors | 3 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A12V11 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A12.V11.T30 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V37. Failure of biometrics sensors | V37 | V37 | A12V37 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A12.V37.T2 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V37. Failure of biometrics sensors | V37 | V37 | A12V37 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A12.V37.T8 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V37. Failure of biometrics sensors | V37 | V37 | A12V37 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A12.V37.T10 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V37. Failure of biometrics sensors | V37 | V37 | A12V37 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A12.V37.T14 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] | V32 | V32 | A12V32 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A12.V32.T9 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] | V32 | V32 | A12V32 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A12.V32.T22 | 9 | 9 |
| A12 | Scanners & detectors | 3 | V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] | V32 | V32 | A12V32 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A12.V32.T30 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V33. High error rates of biometric identification (esp. face-based recognition) | V33 | V33 | A12V33 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A12.V33.T8 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V33. High error rates of biometric identification (esp. face-based recognition) | V33 | V33 | A12V33 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A12.V33.T14 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V33. High error rates of biometric identification (esp. face-based recognition) | V33 | V33 | A12V33 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A12.V33.T11 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V33. High error rates of biometric identification (esp. face-based recognition) | V33 | V33 | A12V33 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A12.V33.T30 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A12.V29.T2 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A12.V29.T6 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A12.V29.T7 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A12.V29.T8 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A12.V29.T9 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A12.V29.T10 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A12.V29.T11 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A12.V29.T12 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A12V29 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A12.V29.T13 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A12.V39.T14 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A12.V39.T16 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A12.V39.T22 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A12.V39.T30 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A12.V39.T12 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T19. Jamming | T19 | T19 | 2 | A12.V39.T19 | 5 | 5 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A12.V39.T20 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A12.V39.T24 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A12.V39.T29 | 5 | 5 |
| A12 | Scanners & detectors | 3 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A12V39 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A12.V39.T2 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V22. Collision of tag traffic / Radio-frequency interference | V22 | V22 | A12V22 | 3 | T18. Blocking | T18 | T18 | 2 | A12.V22.T18 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V22. Collision of tag traffic / Radio-frequency interference | V22 | V22 | A12V22 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A12.V22.T13 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A12V38 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A12.V38.T10 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A12V38 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A12.V38.T11 | 5 | 5 |
| A12 | Scanners & detectors | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A12V38 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A12.V38.T12 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A12V38 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A12.V38.T13 | 7 | 7 |
| A12 | Scanners & detectors | 3 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A12V38 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A12.V38.T30 | 6 | 6 |
| A12 | Scanners & detectors | 3 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A12V18 | 4 | T31. Data linkability | T31 | T31 | 4 | A12.V18.T31 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A12V18 | 4 | T32. Profiling | T32 | T32 | 4 | A12.V18.T32 | 8 | 8 |
| A12 | Scanners & detectors | 3 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A12V18 | 4 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A12.V18.T33 | 8 | 8 |
| A13 | Networks | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A13V1 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A13.V1.T6 | 8 | 8 |
| A13 | Networks | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A13V1 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A13.V1.T8 | 8 | 8 |
| A13 | Networks | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A13V1 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A13.V1.T11 | 7 | 7 |
| A13 | Networks | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A13V1 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A13.V1.T12 | 8 | 8 |
| A13 | Networks | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A13V1 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A13.V1.T13 | 9 | 9 |
| A13 | Networks | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A13V1 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A13.V1.T14 | 9 | 9 |
| A13 | Networks | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A13V1 | 3 | T27. Trade union/labor strikes | T27 | T27 | 3 | A13.V1.T27 | 8 | 8 |
| A13 | Networks | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A13V2 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A13.V2.T28 | 10 | 10 |
| A13 | Networks | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A13V3 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A13.V3.T1 | 8 | 8 |
| A13 | Networks | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A13V3 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A13.V3.T6 | 8 | 8 |
| A13 | Networks | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A13V3 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A13.V3.T7 | 8 | 8 |
| A13 | Networks | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A13V3 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A13.V3.T9 | 7 | 7 |
| A13 | Networks | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A13V3 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A13.V3.T22 | 9 | 9 |
| A13 | Networks | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A13V3 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A13.V3.T23 | 8 | 8 |
| A13 | Networks | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A13V3 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A13.V3.T25 | 8 | 8 |
| A13 | Networks | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A13V3 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A13.V3.T28 | 9 | 9 |
| A13 | Networks | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A13V4 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A13.V4.T13 | 10 | 10 |
| A13 | Networks | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A13V4 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A13.V4.T14 | 10 | 10 |
| A13 | Networks | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A13V5 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A13.V5.T8 | 9 | 9 |
| A13 | Networks | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A13V5 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A13.V5.T9 | 8 | 8 |
| A13 | Networks | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A13V5 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A13.V5.T10 | 9 | 9 |
| A13 | Networks | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A13V5 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A13.V5.T11 | 8 | 8 |
| A13 | Networks | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A13V5 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A13.V5.T14 | 10 | 10 |
| A13 | Networks | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A13V5 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A13.V5.T30 | 9 | 9 |
| A13 | Networks | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A13V6 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A13.V6.T9 | 7 | 7 |
| A13 | Networks | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A13V6 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A13.V6.T22 | 9 | 9 |
| A13 | Networks | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A13V6 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A13.V6.T11 | 7 | 7 |
| A13 | Networks | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A13V6 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A13.V6.T12 | 8 | 8 |
| A13 | Networks | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A13V6 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A13.V6.T30 | 8 | 8 |
| A13 | Networks | 4 | V8. Dependency on power systems | V8. | V8 | A13V8 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A13.V8.T1 | 8 | 8 |
| A13 | Networks | 4 | V8. Dependency on power systems | V8. | V8 | A13V8 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A13.V8.T22 | 9 | 9 |
| A13 | Networks | 4 | V8. Dependency on power systems | V8. | V8 | A13V8 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A13.V8.T25 | 8 | 8 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A13.V21.T2 | 10 | 10 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A13.V21.T3 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A13.V21.T5 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A13.V21.T6 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A13.V21.T7 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A13.V21.T8 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A13.V21.T9 | 8 | 8 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A13.V21.T10 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A13.V21.T14 | 10 | 10 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A13.V21.T15 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T17. Side channel attack | T17 | T17 | 2 | A13.V21.T17 | 8 | 8 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T18. Blocking | T18 | T18 | 2 | A13.V21.T18 | 8 | 8 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T19. Jamming | T19 | T19 | 2 | A13.V21.T19 | 7 | 7 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A13.V21.T20 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A13.V21.T21 | 10 | 10 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A13.V21.T24 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A13.V21.T29 | 7 | 7 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A13.V21.T5 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A13.V21.T6 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A13.V21.T8 | 9 | 9 |
| A13 | Networks | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A13V21 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A13.V21.T14 | 10 | 10 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A13.V39.T1 | 9 | 9 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A13.V39.T4 | 8 | 8 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A13.V39.T8 | 9 | 9 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A13.V39.T10 | 9 | 9 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A13.V39.T12 | 9 | 9 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T19. Jamming | T19 | T19 | 2 | A13.V39.T19 | 7 | 7 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A13.V39.T20 | 9 | 9 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A13.V39.T24 | 9 | 9 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A13.V39.T29 | 7 | 7 |
| A13 | Networks | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A13V39 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A13.V39.T2 | 10 | 10 |
| A14 | State databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A14V1 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A14.V1.T6 | 8 | 8 |
| A14 | State databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A14V1 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A14.V1.T8 | 8 | 8 |
| A14 | State databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A14V1 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A14.V1.T11 | 7 | 7 |
| A14 | State databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A14V1 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A14.V1.T12 | 8 | 8 |
| A14 | State databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A14V1 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A14.V1.T13 | 9 | 9 |
| A14 | State databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A14V1 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A14.V1.T14 | 9 | 9 |
| A14 | State databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A14V1 | 3 | T27. Trade union/labor strikes | T27 | T27 | 3 | A14.V1.T27 | 8 | 8 |
| A14 | State databases | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A14V9 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A14.V9.T1 | 9 | 9 |
| A14 | State databases | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A14V9 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A14.V9.T2 | 10 | 10 |
| A14 | State databases | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A14V9 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A14.V9.T5 | 9 | 9 |
| A14 | State databases | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A14V9 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A14.V9.T22 | 10 | 10 |
| A14 | State databases | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A14V9 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A14.V9.T24 | 9 | 9 |
| A14 | State databases | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A14V9 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A14.V9.T25 | 9 | 9 |
| A14 | State databases | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A14V9 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A14.V9.T29 | 7 | 7 |
| A14 | State databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A14V10 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A14.V10.T1 | 8 | 8 |
| A14 | State databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A14V10 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A14.V10.T11 | 7 | 7 |
| A14 | State databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A14V10 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A14.V10.T12 | 8 | 8 |
| A14 | State databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A14V10 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A14.V10.T22 | 9 | 9 |
| A14 | State databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A14V10 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A14.V10.T25 | 8 | 8 |
| A14 | State databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A14V10 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A14.V10.T28 | 9 | 9 |
| A14 | State databases | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A14V18 | 5 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A14.V18.T30 | 10 | 10 |
| A14 | State databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A14V19 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A14.V19.T2 | 10 | 10 |
| A14 | State databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A14V19 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A14.V19.T3 | 9 | 9 |
| A14 | State databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A14V19 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A14.V19.T6 | 9 | 9 |
| A14 | State databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A14V19 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A14.V19.T8 | 9 | 9 |
| A14 | State databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A14V19 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A14.V19.T12 | 9 | 9 |
| A14 | State databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A14V19 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A14.V19.T13 | 10 | 10 |
| A14 | State databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A14V19 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A14.V19.T26 | 10 | 10 |
| A14 | State databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A14V20 | 5 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A14.V20.T3 | 10 | 10 |
| A14 | State databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A14V20 | 5 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A14.V20.T11 | 9 | 9 |
| A14 | State databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A14V20 | 5 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A14.V20.T12 | 10 | 10 |
| A14 | State databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A14V20 | 5 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A14.V20.T13 | 11 | 11 |
| A14 | State databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A14V20 | 5 | T26. State surveillance on citizens | T26 | T26 | 5 | A14.V20.T26 | 11 | 11 |
| A14 | State databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A14V20 | 5 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A14.V20.T30 | 10 | 10 |
| A14 | State databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A14V20 | 5 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A14.V20.T8 | 10 | 10 |
| A14 | State databases | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A14V28 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A14.V28.T12 | 7 | 7 |
| A14 | State databases | 4 | V35. High data linkability | V35 | V35 | A14V35 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A14.V35.T3 | 9 | 9 |
| A14 | State databases | 4 | V35. High data linkability | V35 | V35 | A14V35 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A14.V35.T12 | 9 | 9 |
| A14 | State databases | 4 | V35. High data linkability | V35 | V35 | A14V35 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A14.V35.T13 | 10 | 10 |
| A14 | State databases | 4 | V35. High data linkability | V35 | V35 | A14V35 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A14.V35.T26 | 10 | 10 |
| A14 | State databases | 4 | V35. High data linkability | V35 | V35 | A14V35 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A14.V35.T8 | 9 | 9 |
| A14 | State databases | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A14V36 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A14.V36.T10 | 9 | 9 |
| A14 | State databases | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A14V36 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A14.V36.T12 | 9 | 9 |
| A14 | State databases | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A14V36 | 4 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A14.V36.T23 | 9 | 9 |
| A14 | State databases | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A14V36 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A14.V36.T30 | 9 | 9 |
| A14 | State databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A14V38 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A14.V38.T10 | 9 | 9 |
| A14 | State databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A14V38 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A14.V38.T11 | 8 | 8 |
| A14 | State databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A14V38 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A14.V38.T12 | 9 | 9 |
| A14 | State databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A14V38 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A14.V38.T13 | 10 | 10 |
| A14 | State databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A14V38 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A14.V38.T30 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A15V1 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A15.V1.T6 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A15V1 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A15.V1.T8 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A15V1 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A15.V1.T11 | 7 | 7 |
| A15 | Commercial and other databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A15V1 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A15.V1.T12 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A15V1 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A15.V1.T13 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A15V1 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A15.V1.T14 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A15V1 | 3 | T27. Trade union/labor strikes | T27 | T27 | 3 | A15.V1.T27 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A15V2 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A15.V2.T28 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A15V3 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A15.V3.T1 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A15V3 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A15.V3.T6 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A15V3 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A15.V3.T7 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A15V3 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A15.V3.T9 | 7 | 7 |
| A15 | Commercial and other databases | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A15V3 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A15.V3.T22 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A15V3 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A15.V3.T23 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A15V3 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A15.V3.T25 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A15V3 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A15.V3.T28 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A15.V10.T2 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A15.V10.T6 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A15.V10.T7 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A15.V10.T8 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A15.V10.T9 | 7 | 7 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A15.V10.T10 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A15.V10.T11 | 7 | 7 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A15.V10.T12 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A15.V10.T13 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A15V10 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A15.V10.T14 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A15V18 | 5 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A15.V18.T16 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A15V18 | 5 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A15.V18.T22 | 11 | 11 |
| A15 | Commercial and other databases | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A15V18 | 5 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A15.V18.T30 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A15V18 | 5 | T26. State surveillance on citizens | T26 | T26 | 5 | A15.V18.T26 | 11 | 11 |
| A15 | Commercial and other databases | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A15V18 | 5 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A15.V18.T30 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A15V19 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A15.V19.T2 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A15V19 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A15.V19.T3 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A15V19 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A15.V19.T6 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A15V19 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A15.V19.T8 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A15V19 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A15.V19.T12 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A15V19 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A15.V19.T13 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A15V19 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A15.V19.T26 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A15V20 | 5 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A15.V20.T3 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A15V20 | 5 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A15.V20.T11 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A15V20 | 5 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A15.V20.T12 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A15V20 | 5 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A15.V20.T13 | 11 | 11 |
| A15 | Commercial and other databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A15V20 | 5 | T26. State surveillance on citizens | T26 | T26 | 5 | A15.V20.T26 | 11 | 11 |
| A15 | Commercial and other databases | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A15V20 | 5 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A15.V20.T30 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A15V28 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A15.V28.T8 | 7 | 7 |
| A15 | Commercial and other databases | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A15V28 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A15.V28.T12 | 7 | 7 |
| A15 | Commercial and other databases | 4 | V35. High data linkability | V35 | V35 | A15V35 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A15.V35.T3 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V35. High data linkability | V35 | V35 | A15V35 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A15.V35.T12 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V35. High data linkability | V35 | V35 | A15V35 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A15.V35.T13 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V35. High data linkability | V35 | V35 | A15V35 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A15.V35.T26 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V35. High data linkability | V35 | V35 | A15V35 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A15.V35.T8 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A15V36 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A15.V36.T10 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A15V36 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A15.V36.T12 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A15V36 | 4 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A15.V36.T23 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) | V36 | V36 | A15V36 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A15.V36.T30 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A15V38 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A15.V38.T10 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A15V38 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A15.V38.T11 | 8 | 8 |
| A15 | Commercial and other databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A15V38 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A15.V38.T12 | 9 | 9 |
| A15 | Commercial and other databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A15V38 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A15.V38.T13 | 10 | 10 |
| A15 | Commercial and other databases | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A15V38 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A15.V38.T30 | 9 | 9 |
| A16 | Temporary handset airport guides | 2 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A16V4 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A16.V4.T13 | 8 | 8 |
| A16 | Temporary handset airport guides | 2 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A16V4 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A16.V4.T14 | 8 | 8 |
| A16 | Temporary handset airport guides | 2 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A16V5 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A16.V5.T8 | 5 | 5 |
| A16 | Temporary handset airport guides | 2 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A16V5 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A16.V5.T9 | 4 | 4 |
| A16 | Temporary handset airport guides | 2 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A16V5 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A16.V5.T10 | 5 | 5 |
| A16 | Temporary handset airport guides | 2 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A16V5 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A16.V5.T11 | 4 | 4 |
| A16 | Temporary handset airport guides | 2 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A16V5 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A16.V5.T14 | 6 | 6 |
| A16 | Temporary handset airport guides | 2 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A16V5 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A16.V5.T30 | 5 | 5 |
| A16 | Temporary handset airport guides | 2 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A16V6 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A16.V6.T9 | 4 | 4 |
| A16 | Temporary handset airport guides | 2 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A16V6 | 2 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A16.V6.T22 | 6 | 6 |
| A16 | Temporary handset airport guides | 2 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A16V6 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A16.V6.T11 | 4 | 4 |
| A16 | Temporary handset airport guides | 2 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A16V6 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A16.V6.T12 | 5 | 5 |
| A16 | Temporary handset airport guides | 2 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A16V6 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A16.V6.T30 | 5 | 5 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A17.V13.T1 | 7 | 7 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A17.V13.T2 | 8 | 8 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A17.V13.T4 | 6 | 6 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A17.V13.T5 | 7 | 7 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A17.V13.T15 | 7 | 7 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T17. Side channel attack | T17 | T17 | 2 | A17.V13.T17 | 6 | 6 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T18. Blocking | T18 | T18 | 2 | A17.V13.T18 | 6 | 6 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T19. Jamming | T19 | T19 | 2 | A17.V13.T19 | 5 | 5 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A17.V13.T20 | 7 | 7 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A17.V13.T1 | 7 | 7 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A17.V13.T2 | 8 | 8 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A17.V13.T4 | 6 | 6 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A17.V13.T5 | 7 | 7 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A17.V13.T15 | 7 | 7 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T17. Side channel attack | T17 | T17 | 2 | A17.V13.T17 | 6 | 6 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T18. Blocking | T18 | T18 | 2 | A17.V13.T18 | 6 | 6 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T19. Jamming | T19 | T19 | 2 | A17.V13.T19 | 5 | 5 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A17.V13.T20 | 7 | 7 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A17.V13.T21 | 8 | 8 |
| A17 | Luggage and goods | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A17V13 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A17.V13.T22 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A18.V1.T2 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A18.V1.T3 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A18.V1.T5 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A18.V1.T6 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A18.V1.T8 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A18.V1.T9 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A18.V1.T7 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A18.V1.T10 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A18.V1.T11 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A18.V1.T12 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V1.T14 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A18.V1.T16 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A18.V1.T22 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A18.V1.T23 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T27. Trade union/labor strikes | T27 | T27 | 3 | A18.V1.T27 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V1.T14 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A18V1 | 3 | T27. Trade union/labor strikes | T27 | T27 | 3 | A18.V1.T27 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A18V2 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A18.V2.T1 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A18V2 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A18.V2.T2 | 9 | 9 |
| A18 | Check-in infrastructure | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A18V2 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A18.V2.T5 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A18V2 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A18.V2.T22 | 9 | 9 |
| A18 | Check-in infrastructure | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A18V2 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A18.V2.T24 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A18V2 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A18.V2.T25 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A18V2 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A18.V2.T28 | 9 | 9 |
| A18 | Check-in infrastructure | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A18V3 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A18.V3.T1 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A18V3 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A18.V3.T6 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A18V3 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A18.V3.T7 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A18V3 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A18.V3.T9 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A18V3 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A18.V3.T22 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A18V3 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A18.V3.T23 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A18V3 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A18.V3.T25 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A18V3 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A18.V3.T28 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A18.V12.T2 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T6. Social engineering attack | T6. | T6 | 4 | A18.V12.T6 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A18.V12.T7 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A18.V12.T8 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A18.V12.T9 | 5 | 5 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A18.V12.T10 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A18.V12.T11 | 5 | 5 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A18.V12.T12 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A18.V12.T13 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V12.T14 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A18.V12.T16 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A18.V12.T22 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A18.V12.T30 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A18.V12.T11 | 5 | 5 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A18.V12.T12 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A18.V12.T30 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A18V12 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A18.V12.T13 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A18V14 | 4 | T27. Trade union/labor strikes | T27 | T27 | 3 | A18.V14.T27 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V23. Over dependency on biometrics | V23 | V23 | A18V23 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A18.V23.T3 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V23. Over dependency on biometrics | V23 | V23 | A18V23 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A18.V23.T11 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V23. Over dependency on biometrics | V23 | V23 | A18V23 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A18.V23.T12 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V23. Over dependency on biometrics | V23 | V23 | A18V23 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V23.T14 | 9 | 9 |
| A18 | Check-in infrastructure | 3 | V23. Over dependency on biometrics | V23 | V23 | A18V23 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A18.V23.T30 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V33. High error rates of biometric identification (esp. face-based recognition) | V33 | V33 | A18V33 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A18.V33.T8 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V33. High error rates of biometric identification (esp. face-based recognition) | V33 | V33 | A18V33 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V33.T14 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V33. High error rates of biometric identification (esp. face-based recognition) | V33 | V33 | A18V33 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A18.V33.T11 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V33. High error rates of biometric identification (esp. face-based recognition) | V33 | V33 | A18V33 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A18.V33.T30 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V37. Failure of biometrics sensors | V37 | V37 | A18V37 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A18.V37.T2 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V37. Failure of biometrics sensors | V37 | V37 | A18V37 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A18.V37.T8 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V37. Failure of biometrics sensors | V37 | V37 | A18V37 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A18.V37.T10 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V37. Failure of biometrics sensors | V37 | V37 | A18V37 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V37.T14 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A18V6 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A18.V6.T9 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A18V6 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A18.V6.T22 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A18V6 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A18.V6.T11 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A18V6 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A18.V6.T12 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A18V6 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A18.V6.T30 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A18V7 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A18.V7.T10 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A18V7 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A18.V7.T12 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A18V7 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A18.V7.T11 | 5 | 5 |
| A18 | Check-in infrastructure | 3 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A18V7 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V7.T14 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A18V7 | 2 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A18.V7.T23 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V8. Dependency on power systems | V8. | V8 | A18V8 | 2 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A18.V8.T1 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V8. Dependency on power systems | V8. | V8 | A18V8 | 2 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A18.V8.T22 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V8. Dependency on power systems | V8. | V8 | A18V8 | 2 | T25. Malicious power failure attack | T25 | T25 | 3 | A18.V8.T25 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A18.V9.T1 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A18.V9.T2 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A18.V9.T5 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A18.V9.T22 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A18.V9.T24 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A18.V9.T25 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A18.V9.T28 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A18.V9.T13 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V9.T14 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A18.V9.T8 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A18.V9.T9 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A18.V9.T10 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A18.V9.T11 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A18.V9.T14 | 8 | 8 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A18.V9.T30 | 7 | 7 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A18.V9.T9 | 6 | 6 |
| A18 | Check-in infrastructure | 3 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A18V9 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A18.V9.T22 | 8 | 8 |
| A19 | Airport facilities | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A19V2 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A19.V2.T11 | 6 | 6 |
| A19 | Airport facilities | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A19V2 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A19.V2.T12 | 7 | 7 |
| A19 | Airport facilities | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A19V2 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A19.V2.T30 | 7 | 7 |
| A19 | Airport facilities | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A19V2 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A19.V2.T1 | 7 | 7 |
| A19 | Airport facilities | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A19V2 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A19.V2.T22 | 8 | 8 |
| A19 | Airport facilities | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A19V2 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A19.V2.T25 | 7 | 7 |
| A19 | Airport facilities | 3 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A19V2 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A19.V2.T2 | 8 | 8 |
| A19 | Airport facilities | 3 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A19V4 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A19.V4.T3 | 8 | 8 |
| A19 | Airport facilities | 3 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A19V4 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A19.V4.T5 | 8 | 8 |
| A19 | Airport facilities | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A19V5 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A19.V5.T6 | 7 | 7 |
| A19 | Airport facilities | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A19V5 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A19.V5.T8 | 7 | 7 |
| A19 | Airport facilities | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A19V5 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A19.V5.T9 | 6 | 6 |
| A19 | Airport facilities | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A19V5 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A19.V5.T7 | 7 | 7 |
| A19 | Airport facilities | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A19V5 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A19.V5.T10 | 7 | 7 |
| A19 | Airport facilities | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A19V5 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A19.V5.T11 | 6 | 6 |
| A19 | Airport facilities | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A19V6 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A19.V6.T12 | 7 | 7 |
| A19 | Airport facilities | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A19V6 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A19.V6.T14 | 8 | 8 |
| A19 | Airport facilities | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A19V6 | 3 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A19.V6.T16 | 7 | 7 |
| A19 | Airport facilities | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A19V6 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A19.V6.T22 | 8 | 8 |
| A19 | Airport facilities | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A19V6 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A19.V6.T23 | 7 | 7 |
| A19 | Airport facilities | 3 | V8. Dependency on power systems | V8. | V8 | A19V8 | 3 | T27. Trade union/labor strikes | T27 | T27 | 3 | A19.V8.T27 | 7 | 7 |
| A19 | Airport facilities | 3 | V8. Dependency on power systems | V8. | V8 | A19V8 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A19.V8.T8 | 7 | 7 |
| A19 | Airport facilities | 3 | V8. Dependency on power systems | V8. | V8 | A19V8 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A19.V8.T14 | 8 | 8 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A19.V14.T6 | 8 | 8 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A19.V14.T3 | 8 | 8 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A19.V14.T11 | 7 | 7 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A19.V14.T12 | 8 | 8 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A19.V14.T13 | 9 | 9 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A19.V14.T26 | 9 | 9 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A19.V14.T30 | 8 | 8 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A19.V14.T9 | 7 | 7 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A19.V14.T22 | 9 | 9 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A19.V14.T30 | 8 | 8 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A19.V14.T1 | 8 | 8 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A19.V14.T2 | 9 | 9 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A19.V14.T5 | 8 | 8 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A19.V14.T22 | 9 | 9 |
| A19 | Airport facilities | 3 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A19V14 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A19.V14.T24 | 8 | 8 |
| A19 | Airport facilities | 3 | V16. Inappropriate expansion of the trust perimeter | V16 | V16 | A19V16 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A19.V16.T25 | 8 | 8 |
| A19 | Airport facilities | 3 | V16. Inappropriate expansion of the trust perimeter | V16 | V16 | A19V16 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A19.V16.T28 | 9 | 9 |
| A19 | Airport facilities | 3 | V16. Inappropriate expansion of the trust perimeter | V16 | V16 | A19V16 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A19.V16.T2 | 9 | 9 |
| A19 | Airport facilities | 3 | V20. Lack of respect to the transparency principle | V20 | V20 | A19V20 | 2 | T6. Social engineering attack | T6. | T6 | 4 | A19.V20.T6 | 6 | 6 |
| A19 | Airport facilities | 3 | V20. Lack of respect to the transparency principle | V20 | V20 | A19V20 | 2 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A19.V20.T7 | 6 | 6 |
| A19 | Airport facilities | 3 | V20. Lack of respect to the transparency principle | V20 | V20 | A19V20 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A19.V20.T8 | 6 | 6 |
| A19 | Airport facilities | 3 | V20. Lack of respect to the transparency principle | V20 | V20 | A19V20 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A19.V20.T9 | 5 | 5 |
| A19 | Airport facilities | 3 | V20. Lack of respect to the transparency principle | V20 | V20 | A19V20 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A19.V20.T10 | 6 | 6 |
| A19 | Airport facilities | 3 | V20. Lack of respect to the transparency principle | V20 | V20 | A19V20 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A19.V20.T11 | 5 | 5 |
| A19 | Airport facilities | 3 | V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] | V32 | V32 | A19V32 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A19.V32.T12 | 8 | 8 |
| A19 | Airport facilities | 3 | V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] | V32 | V32 | A19V32 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A19.V32.T13 | 9 | 9 |
| A19 | Airport facilities | 3 | V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] | V32 | V32 | A19V32 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A19.V32.T14 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V8. Dependency on power systems | V8. | V8 | A2V8 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A2.V8.T1 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V8. Dependency on power systems | V8. | V8 | A2V8 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A2.V8.T22 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V8. Dependency on power systems | V8. | V8 | A2V8 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A2.V8.T25 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A2V1 | 5 | T6. Social engineering attack | T6. | T6 | 4 | A2.V1.T6 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A2V1 | 5 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A2.V1.T8 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A2V1 | 5 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V1.T11 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A2V1 | 5 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V1.T12 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A2V1 | 5 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A2.V1.T13 | 11 | 11 |
| A2 | Electronic visa issuing process | 4 | V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. | V1. | V1 | A2V1 | 5 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A2.V1.T14 | 11 | 11 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A2.V12.T9 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A2.V12.T10 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V12.T11 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V12.T12 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V12.T30 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A2.V12.T9 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A2.V12.T10 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V12.T11 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V12.T12 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V12.T30 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A2V12 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A2.V12.T13 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A2.V14.T2 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A2.V14.T3 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A2.V14.T5 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A2.V14.T6 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A2.V14.T8 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A2.V14.T9 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A2.V14.T7 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A2.V14.T10 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V14.T11 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V14.T12 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A2.V14.T14 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A2.V14.T16 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A2.V14.T22 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A2.V14.T23 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] | V14 | V14 | A2V14 | 4 | T27. Trade union/labor strikes | T27 | T27 | 3 | A2.V14.T27 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A2V3 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A2.V3.T1 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A2V3 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A2.V3.T6 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A2V3 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A2.V3.T7 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A2V3 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A2.V3.T9 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A2V3 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A2.V3.T22 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A2V3 | 4 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A2.V3.T23 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A2V3 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A2.V3.T25 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A2V3 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A2.V3.T28 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A2V7 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A2.V7.T10 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A2V7 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V7.T12 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A2V7 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V7.T11 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A2V7 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A2.V7.T14 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] | V7. | V7 | A2V7 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A2.V7.T23 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A2V5 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A2.V5.T8 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A2V5 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A2.V5.T9 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A2V5 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A2.V5.T10 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A2V5 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V5.T11 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A2V5 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A2.V5.T14 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A2V5 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V5.T30 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V23. Over dependency on biometrics | V23 | V23 | A2V23 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A2.V23.T3 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V23. Over dependency on biometrics | V23 | V23 | A2V23 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V23.T11 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V23. Over dependency on biometrics | V23 | V23 | A2V23 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V23.T12 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V23. Over dependency on biometrics | V23 | V23 | A2V23 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A2.V23.T14 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V23. Over dependency on biometrics | V23 | V23 | A2V23 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V23.T30 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A2V6 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A2.V6.T9 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A2V6 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A2.V6.T22 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A2V6 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V6.T11 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A2V6 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V6.T12 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A2V6 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V6.T30 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A2.V38.T2 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A2.V38.T3 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A2.V38.T5 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A2.V38.T6 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A2.V38.T7 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A2.V38.T8 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A2.V38.T9 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A2.V38.T10 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A2.V38.T14 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A2.V38.T15 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T17. Side channel attack | T17 | T17 | 2 | A2.V38.T17 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T18. Blocking | T18 | T18 | 2 | A2.V38.T18 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T19. Jamming | T19 | T19 | 2 | A2.V38.T19 | 6 | 6 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A2.V38.T20 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A2.V38.T21 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A2.V38.T24 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A2.V38.T29 | 6 | 6 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A2.V38.T10 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V38.T11 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V38.T12 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A2.V38.T13 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V38.T30 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V15. Insufficient equipment | V15 | V15 | A2V15 | 2 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A2.V15.T3 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V15. Insufficient equipment | V15 | V15 | A2V15 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V15.T12 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V15. Insufficient equipment | V15 | V15 | A2V15 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A2.V15.T13 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V15. Insufficient equipment | V15 | V15 | A2V15 | 2 | T26. State surveillance on citizens | T26 | T26 | 5 | A2.V15.T26 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V15. Insufficient equipment | V15 | V15 | A2V15 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V15.T30 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V15. Insufficient equipment | V15 | V15 | A2V15 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V15.T30 | 7 | 7 |
| A2 | Electronic visa issuing process | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A2V20 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A2.V20.T3 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A2V20 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A2.V20.T11 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A2V20 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V20.T12 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A2V20 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A2.V20.T13 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A2V20 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A2.V20.T26 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A2V20 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A2.V20.T30 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A2V20 | 4 | T32. Profiling | T32 | T32 | 4 | A2.V20.T32 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A2V21 | 0 | T34. Trivialisation of unique identifiers | T34 | T34 | 4 | A2.V21.T34 | 5 | 5 |
| A2 | Electronic visa issuing process | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A2V38 | 3 | T34. Trivialisation of unique identifiers | T34 | T34 | 4 | A2.V38.T34 | 8 | 8 |
| A2 | Electronic visa issuing process | 4 | V40. Lack of respect to the legitimacy of data processing, e.g. consent | V40 | V40 | A2V40 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A2.V40.T12 | 9 | 9 |
| A2 | Electronic visa issuing process | 4 | V41. Lack of respect to the data conservation principle | V41 | V41 | A2V41 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A2.V41.T13 | 10 | 10 |
| A2 | Electronic visa issuing process | 4 | V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). | V42 | V42 | A2V42 | 5 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A2.V42.T13 | 11 | 11 |
| A20 | Cars / vehicles | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A20V2 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A20.V2.T9 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A20V2 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A20.V2.T22 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A20V2 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A20.V2.T11 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A20V2 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V2.T12 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A20V2 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A20.V2.T30 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A20V2 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A20.V2.T1 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A20V2 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A20.V2.T22 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A20.V4.T25 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A20.V4.T2 | 10 | 10 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A20.V4.T3 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A20.V4.T5 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A20.V4.T6 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A20.V4.T7 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A20.V4.T8 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A20.V4.T9 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A20.V4.T10 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A20V4 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A20.V4.T14 | 10 | 10 |
| A20 | Cars / vehicles | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A20V6 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A20.V6.T15 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A20V6 | 3 | T17. Side channel attack | T17 | T17 | 2 | A20.V6.T17 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A20V6 | 3 | T18. Blocking | T18 | T18 | 2 | A20.V6.T18 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A20V6 | 3 | T19. Jamming | T19 | T19 | 2 | A20.V6.T19 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A20V6 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A20.V6.T20 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V8. Dependency on power systems | V8. | V8 | A20V8 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A20.V8.T21 | 10 | 10 |
| A20 | Cars / vehicles | 4 | V8. Dependency on power systems | V8. | V8 | A20V8 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A20.V8.T24 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V8. Dependency on power systems | V8. | V8 | A20V8 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A20.V8.T29 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A20.V9.T1 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A20.V9.T11 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V9.T12 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A20.V9.T22 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A20.V9.T25 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A20.V9.T28 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A20.V9.T9 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A20.V9.T10 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A20.V9.T11 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V9.T12 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A20.V9.T30 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A20.V9.T9 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A20.V9.T10 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A20.V9.T11 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V9.T12 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A20.V9.T30 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A20V9 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A20.V9.T13 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A20V10 | 2 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A20.V10.T22 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A20V10 | 2 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A20.V10.T4 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A20V10 | 2 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A20.V10.T3 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A20V10 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V10.T12 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A20V10 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A20.V10.T13 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A20V10 | 2 | T26. State surveillance on citizens | T26 | T26 | 5 | A20.V10.T26 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A20.V12.T30 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A20.V12.T2 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A20.V12.T3 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T6. Social engineering attack | T6. | T6 | 4 | A20.V12.T6 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A20.V12.T8 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V12.T12 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A20.V12.T13 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T26. State surveillance on citizens | T26 | T26 | 5 | A20.V12.T26 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A20.V12.T3 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A20.V12.T11 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A20V12 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V12.T12 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V17. Lack of dependable sensors, GPS | V17 | V17 | A20V17 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A20.V17.T13 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V17. Lack of dependable sensors, GPS | V17 | V17 | A20V17 | 3 | T26. State surveillance on citizens | T26 | T26 | 5 | A20.V17.T26 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A20V18 | 1 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A20.V18.T30 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A20V18 | 1 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A20.V18.T8 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A20V18 | 1 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V18.T12 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A20V18 | 1 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A20.V18.T10 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A20V18 | 1 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A20.V18.T11 | 5 | 5 |
| A20 | Cars / vehicles | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A20V19 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V19.T12 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A20V19 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A20.V19.T13 | 10 | 10 |
| A20 | Cars / vehicles | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A20V19 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A20.V19.T30 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A20V19 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A20.V19.T1 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A20V19 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A20.V19.T4 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A20V19 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A20.V19.T8 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A20V19 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A20.V19.T10 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A20V20 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A20.V20.T12 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A20V20 | 3 | T19. Jamming | T19 | T19 | 2 | A20.V20.T19 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A20V20 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A20.V20.T20 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A20V20 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A20.V20.T24 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A20V20 | 3 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A20.V20.T29 | 6 | 6 |
| A20 | Cars / vehicles | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A20V20 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A20.V20.T2 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A20V28 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A20.V28.T2 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A20V28 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A20.V28.T3 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A20V38 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A20.V38.T5 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A20V38 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A20.V38.T6 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A20V38 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A20.V38.T7 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A20V38 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A20.V38.T8 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A20V38 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A20.V38.T9 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A20.V39.T10 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A20.V39.T14 | 10 | 10 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A20.V39.T15 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T17. Side channel attack | T17 | T17 | 2 | A20.V39.T17 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T18. Blocking | T18 | T18 | 2 | A20.V39.T18 | 8 | 8 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T19. Jamming | T19 | T19 | 2 | A20.V39.T19 | 7 | 7 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A20.V39.T20 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A20.V39.T21 | 10 | 10 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A20.V39.T24 | 9 | 9 |
| A20 | Cars / vehicles | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A20V39 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A20.V39.T29 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A3.V13.T1 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A3.V13.T2 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A3.V13.T4 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T5. Man in the middle attack | T5. | T5 | 3 | A3.V13.T5 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A3.V13.T15 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T17. Side channel attack | T17 | T17 | 2 | A3.V13.T17 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T18. Blocking | T18 | T18 | 2 | A3.V13.T18 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T19. Jamming | T19 | T19 | 2 | A3.V13.T19 | 4 | 4 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A3.V13.T20 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A3.V13.T21 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A3.V13.T1 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A3.V13.T2 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A3.V13.T4 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T5. Man in the middle attack | T5. | T5 | 3 | A3.V13.T5 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A3.V13.T15 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T17. Side channel attack | T17 | T17 | 2 | A3.V13.T17 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T18. Blocking | T18 | T18 | 2 | A3.V13.T18 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T19. Jamming | T19 | T19 | 2 | A3.V13.T19 | 4 | 4 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A3.V13.T20 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A3.V13.T21 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A3V13 | 2 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A3.V13.T22 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V25. Actual RFID range longer than standard | V25 | V25 | A3V25 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A3.V25.T8 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V25. Actual RFID range longer than standard | V25 | V25 | A3V25 | 2 | T5. Man in the middle attack | T5. | T5 | 3 | A3.V25.T5 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V25. Actual RFID range longer than standard | V25 | V25 | A3V25 | 2 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A3.V25.T20 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A3.V12.T1 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A3.V12.T2 | 8 | 8 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A3.V12.T5 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A3.V12.T22 | 8 | 8 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A3.V12.T24 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A3.V12.T25 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A3.V12.T28 | 8 | 8 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A3.V12.T12 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A3.V12.T30 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A3.V12.T9 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A3.V12.T10 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A3.V12.T11 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A3.V12.T12 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A3.V12.T30 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A3V12 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A3.V12.T13 | 8 | 8 |
| A3 | Luggage and goods handling | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A3V5 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A3.V5.T8 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A3V5 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A3.V5.T9 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A3V5 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A3.V5.T10 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A3V5 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A3.V5.T11 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A3V5 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A3.V5.T14 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A3V5 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A3.V5.T30 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V15. Insufficient equipment | V15 | V15 | A3V15 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A3.V15.T11 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V15. Insufficient equipment | V15 | V15 | A3V15 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A3.V15.T30 | 8 | 8 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A3.V24.T2 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T6. Social engineering attack | T6. | T6 | 4 | A3.V24.T6 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A3.V24.T7 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A3.V24.T8 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A3.V24.T9 | 5 | 5 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A3.V24.T14 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A3.V24.T15 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A3.V24.T16 | 6 | 6 |
| A3 | Luggage and goods handling | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A3V24 | 2 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A3.V24.T21 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A3V6 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A3.V6.T9 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A3V6 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A3.V6.T22 | 9 | 9 |
| A3 | Luggage and goods handling | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A3V6 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A3.V6.T11 | 7 | 7 |
| A3 | Luggage and goods handling | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A3V6 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A3.V6.T12 | 8 | 8 |
| A3 | Luggage and goods handling | 3 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A3V6 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A3.V6.T30 | 8 | 8 |
| A4 | Automated traffic management | 4 | V17. Lack of dependable sensors, GPS | V17 | V17 | A4V17 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A4.V17.T22 | 9 | 9 |
| A4 | Automated traffic management | 4 | V17. Lack of dependable sensors, GPS | V17 | V17 | A4V17 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A4.V17.T4 | 7 | 7 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A4.V39.T1 | 9 | 9 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A4.V39.T4 | 8 | 8 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A4.V39.T8 | 9 | 9 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A4.V39.T10 | 9 | 9 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A4.V39.T12 | 9 | 9 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T19. Jamming | T19 | T19 | 2 | A4.V39.T19 | 7 | 7 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A4.V39.T20 | 9 | 9 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A4.V39.T24 | 9 | 9 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A4.V39.T29 | 7 | 7 |
| A4 | Automated traffic management | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A4V39 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A4.V39.T2 | 10 | 10 |
| A4 | Automated traffic management | 4 | V20. Lack of respect to the transparency principle | V20 | V20 | A4V20 | 3 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A4.V20.T33 | 8 | 8 |
| A4 | Automated traffic management | 4 | V40. Lack of respect to the legitimacy of data processing, e.g. consent | V40 | V40 | A4V40 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A4.V40.T13 | 9 | 9 |
| A4 | Automated traffic management | 4 | V41. Lack of respect to the data conservation principle | V41 | V41 | A4V41 | 3 | T32. Profiling | T32 | T32 | 4 | A4.V41.T32 | 8 | 8 |
| A4 | Automated traffic management | 4 | V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). | V42 | V42 | A4V42 | 3 | T31. Data linkability | T31 | T31 | 4 | A4.V42.T31 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A5.V11.T2 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A5.V11.T3 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A5.V11.T5 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A5.V11.T6 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A5.V11.T8 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A5.V11.T9 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A5.V11.T7 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A5.V11.T10 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A5.V11.T11 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A5.V11.T12 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A5.V11.T14 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A5.V11.T16 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A5.V11.T22 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A5.V11.T23 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T27. Trade union/labor strikes | T27 | T27 | 3 | A5.V11.T27 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A5.V11.T14 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A5V11 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A5.V11.T30 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A5.V4.T2 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A5.V4.T6 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A5.V4.T7 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A5.V4.T8 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A5.V4.T9 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A5.V4.T10 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A5.V4.T11 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A5.V4.T12 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A5.V4.T13 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A5V4 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A5.V4.T14 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A5.V24.T16 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A5.V24.T22 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A5.V24.T30 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A5.V24.T8 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A5.V24.T9 | 6 | 6 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A5.V24.T14 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A5.V24.T15 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A5.V24.T16 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A5V24 | 2 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A5.V24.T21 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A5V6 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A5.V6.T9 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A5V6 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A5.V6.T22 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A5V6 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A5.V6.T11 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A5V6 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A5.V6.T12 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A5V6 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A5.V6.T30 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A5V9 | 2 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A5.V9.T24 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A5V9 | 2 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A5.V9.T29 | 5 | 5 |
| A5 | Passports and National ID cards | 4 | V25. Actual RFID range longer than standard | V25 | V25 | A5V25 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A5.V25.T8 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V25. Actual RFID range longer than standard | V25 | V25 | A5V25 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A5.V25.T5 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V25. Actual RFID range longer than standard | V25 | V25 | A5V25 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A5.V25.T20 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V26. RFID tags do not have a turn-off option | V26 | V26 | A5V26 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A5.V26.T20 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V27. Insufficient protection against reverse engineering | V27 | V27 | A5V27 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A5.V27.T15 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V27. Insufficient protection against reverse engineering | V27 | V27 | A5V27 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A5.V27.T20 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A5V28 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A5.V28.T8 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A5V28 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A5.V28.T12 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A5.V12.T1 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A5.V12.T2 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A5.V12.T4 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A5.V12.T5 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A5.V12.T15 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T17. Side channel attack | T17 | T17 | 2 | A5.V12.T17 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T18. Blocking | T18 | T18 | 2 | A5.V12.T18 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T19. Jamming | T19 | T19 | 2 | A5.V12.T19 | 6 | 6 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A5.V12.T20 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A5.V12.T21 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A5.V12.T1 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A5.V12.T2 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A5.V12.T4 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A5.V12.T5 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A5.V12.T15 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T17. Side channel attack | T17 | T17 | 2 | A5.V12.T17 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T18. Blocking | T18 | T18 | 2 | A5.V12.T18 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T19. Jamming | T19 | T19 | 2 | A5.V12.T19 | 6 | 6 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A5.V12.T20 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A5.V12.T21 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A5.V12.T22 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A5.V12.T12 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A5.V12.T30 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A5V12 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A5.V12.T13 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A5V18 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A5.V18.T30 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A5V21 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A5.V21.T2 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A5V21 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A5.V21.T5 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A5V21 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A5.V21.T6 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A5V21 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A5.V21.T8 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A5V21 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A5.V21.T14 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V22. Collision of tag traffic / Radio-frequency interference | V22 | V22 | A5V22 | 2 | T18. Blocking | T18 | T18 | 2 | A5.V22.T18 | 6 | 6 |
| A5 | Passports and National ID cards | 4 | V22. Collision of tag traffic / Radio-frequency interference | V22 | V22 | A5V22 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A5.V22.T13 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A5.V31.T4 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A5.V31.T5 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A5.V31.T6 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A5.V31.T7 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A5.V31.T8 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A5.V31.T10 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A5.V31.T15 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A5.V31.T20 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A5V31 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A5.V31.T24 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A5V38 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A5.V38.T10 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A5V38 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A5.V38.T11 | 7 | 7 |
| A5 | Passports and National ID cards | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A5V38 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A5.V38.T12 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A5V38 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A5.V38.T13 | 9 | 9 |
| A5 | Passports and National ID cards | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A5V38 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A5.V38.T30 | 8 | 8 |
| A5 | Passports and National ID cards | 4 | V41. Lack of respect to the data conservation principle | V41 | V41 | A5V41 | 4 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A5.V41.T33 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A6.V21.T6 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V23. Over dependency on biometrics | V23 | V23 | A6V23 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A6.V23.T3 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V23. Over dependency on biometrics | V23 | V23 | A6V23 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A6.V23.T11 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V23. Over dependency on biometrics | V23 | V23 | A6V23 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V23.T12 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V23. Over dependency on biometrics | V23 | V23 | A6V23 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A6.V23.T14 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V23. Over dependency on biometrics | V23 | V23 | A6V23 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A6.V23.T30 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A6V11 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A6.V11.T2 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A6V11 | 3 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A6.V11.T3 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A6V11 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A6.V11.T11 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A6V11 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V11.T12 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A6V11 | 3 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A6.V11.T14 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V11. Lack of adequate controls in biometrics' enrollment stage | V11 | V11 | A6V11 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A6.V11.T30 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A6.V24.T2 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T6. Social engineering attack | T6. | T6 | 4 | A6.V24.T6 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A6.V24.T7 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A6.V24.T8 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A6.V24.T9 | 6 | 6 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A6.V24.T10 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A6.V24.T11 | 6 | 6 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V24.T12 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A6.V24.T13 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A6.V24.T14 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A6V24 | 2 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A6.V24.T16 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A6V6 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A6.V6.T9 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A6V6 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A6.V6.T22 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A6V6 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A6.V6.T11 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A6V6 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V6.T12 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A6V6 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A6.V6.T30 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A6.V13.T2 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A6.V13.T3 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A6.V13.T5 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A6.V13.T6 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A6.V13.T7 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A6.V13.T8 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A6.V13.T9 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A6.V13.T10 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A6.V13.T14 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A6.V13.T15 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T17. Side channel attack | T17 | T17 | 2 | A6.V13.T17 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T18. Blocking | T18 | T18 | 2 | A6.V13.T18 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T19. Jamming | T19 | T19 | 2 | A6.V13.T19 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A6.V13.T20 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A6.V13.T21 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A6.V13.T24 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A6.V13.T29 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T19. Jamming | T19 | T19 | 2 | A6.V13.T19 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A6.V13.T20 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A6.V13.T21 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V13. Lack of or inappropriate protection of RFID tags | V13 | V13 | A6V13 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A6.V13.T22 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A6.V12.T9 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A6.V12.T10 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A6.V12.T11 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V12.T12 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A6.V12.T30 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A6.V12.T9 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A6.V12.T10 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A6.V12.T11 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V12.T12 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A6.V12.T30 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A6V12 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A6.V12.T13 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T3. Large-scale and/or inappropriate data mining / surveillance / profiling | T3. | T3 | 4 | A6.V21.T3 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V21.T12 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A6.V21.T13 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T26. State surveillance on citizens | T26 | T26 | 5 | A6.V21.T26 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A6.V21.T2 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T5. Man in the middle attack | T5. | T5 | 3 | A6.V21.T5 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A6.V21.T6 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A6.V21.T8 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V21. Inappropriate / inadequate identity management | V21 | V21 | A6V21 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A6.V21.T14 | 10 | 10 |
| A6 | Mobile ‘smart’ devices | 4 | V22. Collision of tag traffic / Radio-frequency interference | V22 | V22 | A6V22 | 2 | T18. Blocking | T18 | T18 | 2 | A6.V22.T18 | 6 | 6 |
| A6 | Mobile ‘smart’ devices | 4 | V22. Collision of tag traffic / Radio-frequency interference | V22 | V22 | A6V22 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A6.V22.T13 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A6.V31.T4 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A6.V31.T5 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A6.V31.T6 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A6.V31.T7 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A6.V31.T8 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A6.V31.T10 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A6.V31.T15 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A6.V31.T20 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A6V31 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A6.V31.T24 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A6V38 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A6.V38.T10 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A6V38 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A6.V38.T11 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A6V38 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V38.T12 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A6V38 | 3 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A6.V38.T13 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V38. Lack of common or harmonised legislation in EU Member States | V38 | V38 | A6V38 | 3 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A6.V38.T30 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A6V10 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A6.V10.T1 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A6V10 | 3 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A6.V10.T11 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A6V10 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V10.T12 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A6V10 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A6.V10.T22 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A6V10 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A6.V10.T25 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A6V10 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A6.V10.T28 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A6.V39.T1 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A6.V39.T4 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A6.V39.T8 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A6.V39.T10 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V39.T12 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T19. Jamming | T19 | T19 | 2 | A6.V39.T19 | 6 | 6 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A6.V39.T20 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A6.V39.T24 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A6.V39.T29 | 6 | 6 |
| A6 | Mobile ‘smart’ devices | 4 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A6V39 | 3 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A6.V39.T2 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A6V34 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A6.V34.T1 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A6V34 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A6.V34.T4 | 8 | 8 |
| A6 | Mobile ‘smart’ devices | 4 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A6V34 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A6.V34.T8 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A6V34 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A6.V34.T10 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A6V34 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A6.V34.T12 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A6V34 | 4 | T19. Jamming | T19 | T19 | 2 | A6.V34.T19 | 7 | 7 |
| A6 | Mobile ‘smart’ devices | 4 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A6V34 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A6.V34.T20 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A6V34 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A6.V34.T24 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A6V19 | 4 | T32. Profiling | T32 | T32 | 4 | A6.V19.T32 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A6V19 | 4 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A6.V19.T33 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V40. Lack of respect to the legitimacy of data processing, e.g. consent | V40 | V40 | A6V40 | 4 | T31. Data linkability | T31 | T31 | 4 | A6.V40.T31 | 9 | 9 |
| A6 | Mobile ‘smart’ devices | 4 | V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). | V42 | V42 | A6V42 | 4 | T32. Profiling | T32 | T32 | 4 | A6.V42.T32 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A7V4 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A7.V4.T14 | 11 | 11 |
| A7 | Health monitoring devices | 5 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A7V5 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A7.V5.T8 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A7V5 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A7.V5.T9 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A7V5 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A7.V5.T10 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A7V5 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A7.V5.T11 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A7V5 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A7.V5.T14 | 11 | 11 |
| A7 | Health monitoring devices | 5 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A7V5 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A7.V5.T30 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A7V6 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A7.V6.T9 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A7V6 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A7.V6.T22 | 11 | 11 |
| A7 | Health monitoring devices | 5 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A7V6 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A7.V6.T11 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A7V6 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A7.V6.T12 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A7V6 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A7.V6.T30 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A7.V24.T2 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T6. Social engineering attack | T6. | T6 | 4 | A7.V24.T6 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A7.V24.T7 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A7.V24.T8 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A7.V24.T9 | 7 | 7 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A7.V24.T14 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A7.V24.T15 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A7.V24.T16 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A7V24 | 2 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A7.V24.T21 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A7V28 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A7.V28.T8 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) | V28 | V28 | A7V28 | 3 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A7.V28.T12 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A7V29 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A7.V29.T9 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A7V29 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A7.V29.T11 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V29. Over-sensitivity of devices (give many false alarms) | V29 | V29 | A7V29 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A7.V29.T30 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V30. Sensitivity to magnetic fields | V30 | V30 | A7V30 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A7.V30.T22 | 11 | 11 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A7.V31.T4 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T5. Man in the middle attack | T5. | T5 | 3 | A7.V31.T5 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A7.V31.T6 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A7.V31.T7 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A7.V31.T8 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A7.V31.T10 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A7.V31.T15 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A7.V31.T20 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V31. Devices & equipment used in unprotected environments | V31 | V31 | A7V31 | 3 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A7.V31.T24 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A7V34 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A7.V34.T1 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A7V34 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A7.V34.T4 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A7V34 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A7.V34.T8 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A7V34 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A7.V34.T10 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A7V34 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A7.V34.T12 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A7V34 | 4 | T19. Jamming | T19 | T19 | 2 | A7.V34.T19 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A7V34 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A7.V34.T20 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V34. Communication of data over unprotected or publicly accessible channels | V34 | V34 | A7V34 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A7.V34.T24 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A7.V39.T1 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T4. Traffic analysis / scan / probe | T4. | T4 | 3 | A7.V39.T4 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A7.V39.T8 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A7.V39.T10 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A7.V39.T12 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T19. Jamming | T19 | T19 | 2 | A7.V39.T19 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag | T20 | T20 | 3 | A7.V39.T20 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T24. Worms, viruses & malicious code | T24 | T24 | 3 | A7.V39.T24 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A7.V39.T29 | 8 | 8 |
| A7 | Health monitoring devices | 5 | V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) | V39 | V39 | A7V39 | 4 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A7.V39.T2 | 11 | 11 |
| A7 | Health monitoring devices | 5 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A7V18 | 4 | T31. Data linkability | T31 | T31 | 4 | A7.V18.T31 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A7V18 | 4 | T32. Profiling | T32 | T32 | 4 | A7.V18.T32 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V18. Lack of respect to the data minimisation and proportionality principles | V18 | V18 | A7V18 | 4 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A7.V18.T33 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A7V19 | 4 | T32. Profiling | T32 | T32 | 4 | A7.V19.T32 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A7V19 | 4 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A7.V19.T33 | 10 | 10 |
| A7 | Health monitoring devices | 5 | V40. Lack of respect to the legitimacy of data processing, e.g. consent | V40 | V40 | A7V40 | 3 | T32. Profiling | T32 | T32 | 4 | A7.V40.T32 | 9 | 9 |
| A7 | Health monitoring devices | 5 | V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). | V42 | V42 | A7V42 | 5 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A7.V42.T33 | 11 | 11 |
| A8 | Travel documents (paper) | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A8V3 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A8.V3.T1 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A8V3 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A8.V3.T6 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A8V3 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A8.V3.T7 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A8V3 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A8.V3.T9 | 7 | 7 |
| A8 | Travel documents (paper) | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A8V3 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A8.V3.T22 | 9 | 9 |
| A8 | Travel documents (paper) | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A8V3 | 4 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A8.V3.T23 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A8V3 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A8.V3.T25 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V3. Lack of back-up / failover procedures | V3. | V3 | A8V3 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A8.V3.T28 | 9 | 9 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T2. Spoofing of credentials / bypass authentication | T2. | T2 | 5 | A8.V12.T2 | 7 | 7 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T6. Social engineering attack | T6. | T6 | 4 | A8.V12.T6 | 6 | 6 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A8.V12.T7 | 6 | 6 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A8.V12.T8 | 6 | 6 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A8.V12.T9 | 5 | 5 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A8.V12.T10 | 6 | 6 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A8.V12.T11 | 5 | 5 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A8.V12.T12 | 6 | 6 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A8.V12.T13 | 7 | 7 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A8.V12.T14 | 7 | 7 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A8.V12.T16 | 6 | 6 |
| A8 | Travel documents (paper) | 3 | V12. Lack of harmonisation and interoperability of procedures | V12 | V12 | A8V12 | 2 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A8.V12.T22 | 7 | 7 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A8.V24.T30 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T6. Social engineering attack | T6. | T6 | 4 | A8.V24.T6 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A8.V24.T7 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A8.V24.T8 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A8.V24.T9 | 7 | 7 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A8.V24.T14 | 9 | 9 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T15. Cloning of credentials and tags (RFID related) | T15 | T15 | 3 | A8.V24.T15 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) | T16 | T16 | 3 | A8.V24.T16 | 8 | 8 |
| A8 | Travel documents (paper) | 3 | V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) | V24 | V24 | A8V24 | 4 | T21. Physical RFID tag destruction | T21 | T21 | 4 | A8.V24.T21 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V2. Excessive dependency on IT systems, network and external infrastructure | V2. | V2 | A9V2 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A9.V2.T28 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A9V3 | 3 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A9.V3.T1 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A9V3 | 3 | T6. Social engineering attack | T6. | T6 | 4 | A9.V3.T6 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A9V3 | 3 | T7. Theft [of cards, devices etc] | T7. | T7 | 4 | A9.V3.T7 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A9V3 | 3 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A9.V3.T9 | 7 | 7 |
| A9 | RFID & barcode readers | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A9V3 | 3 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A9.V3.T22 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A9V3 | 3 | T23. e-visa not accepted at check in | T23 | T23 | 3 | A9.V3.T23 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A9V3 | 3 | T25. Malicious power failure attack | T25 | T25 | 3 | A9.V3.T25 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V3. Lack of back-up / failover procedures | V3. | V3 | A9V3 | 3 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A9.V3.T28 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A9V4 | 4 | T13. Function creep (data used for other purposes that the ones for which they were originally collected) | T13 | T13 | 4 | A9.V4.T13 | 10 | 10 |
| A9 | RFID & barcode readers | 4 | V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc | V4. | V4 | A9V4 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A9.V4.T14 | 10 | 10 |
| A9 | RFID & barcode readers | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A9V5 | 4 | T8. Unauthorised access to / deletion / modification of devices / data etc. | T8. | T8 | 4 | A9.V5.T8 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A9V5 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A9.V5.T9 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A9V5 | 4 | T10. Use erroneous and/or unreliable data | T10 | T10 | 4 | A9.V5.T10 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A9V5 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A9.V5.T11 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A9V5 | 4 | T14. Unauthorized check-in and boarding / identity theft | T14 | T14 | 4 | A9.V5.T14 | 10 | 10 |
| A9 | RFID & barcode readers | 4 | V5. Lack of usability / unfriendly user interface(s) of device(s) | V5. | V5 | A9V5 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A9.V5.T30 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A9V6 | 4 | T9. Loss or misuse [of cards, devices etc] | T9. | T9 | 3 | A9.V6.T9 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A9V6 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A9.V6.T22 | 10 | 10 |
| A9 | RFID & barcode readers | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A9V6 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A9.V6.T11 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A9V6 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A9.V6.T12 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V6. Lack of interoperability between devices and/or technologies and/or systems | V6. | V6 | A9V6 | 4 | T30. Low acceptance of devices / equipment / procedures | T30 | T30 | 4 | A9.V6.T30 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V9. Lack of or inadequate identification, authentication and authorisation controls | V9. | V9 | A9V9 | 3 | T29. MANET/Adhoc network routing attack | T29 | T29 | 2 | A9.V9.T29 | 6 | 6 |
| A9 | RFID & barcode readers | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A9V10 | 4 | T1. Denial of service attack / Flood / Buffer overflow | T1. | T1 | 3 | A9.V10.T1 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A9V10 | 4 | T11. Procedures / instructions not followed | T11 | T11 | 3 | A9.V10.T11 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A9V10 | 4 | T12. Non-compliance with data protection legislation | T12 | T12 | 4 | A9.V10.T12 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A9V10 | 4 | T22. Malfunctioning/breakdown of systems /devices / equipment | T22 | T22 | 4 | A9.V10.T22 | 10 | 10 |
| A9 | RFID & barcode readers | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A9V10 | 4 | T25. Malicious power failure attack | T25 | T25 | 3 | A9.V10.T25 | 9 | 9 |
| A9 | RFID & barcode readers | 4 | V10. Flawed/insufficient design and/or capacity of devices and systems | V10 | V10 | A9V10 | 4 | T28. Adverse weather condition or other disaster | T28 | T28 | 4 | A9.V10.T28 | 10 | 10 |
| A9 | RFID & barcode readers | 4 | V19. Lack of respect to the purpose restriction principle (purpose limitation principle) | V19 | V19 | A9V19 | 3 | T32. Profiling | T32 | T32 | 4 | A9.V19.T32 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V40. Lack of respect to the legitimacy of data processing, e.g. consent | V40 | V40 | A9V40 | 3 | T33. Exclusion of the data subject from the data processing process | T33 | T33 | 4 | A9.V40.T33 | 8 | 8 |
| A9 | RFID & barcode readers | 4 | V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). | V42 | V42 | A9V42 | 4 | T34. Trivialisation of unique identifiers | T34 | T34 | 4 | A9.V42.T34 | 9 | 9 |