Security assurance levels shall be derived by estimating the potential likelihood and business impact of product security failure based on historical precedence and the security status of interdependent systems, in light of the high-level assessment of the proposed product’s estimated business value, operational criticality, and data sensitivity