CC-in-the-Cloud / General

Common Criteria in the Cloud Technical Community
https://cc-in-the-cloud.github.io/
MIT License
6 stars 1 forks source link

German Scheme Feedback: Determine Impact on SARs, 2nd issue #158

Open jgb1128 opened 1 month ago

jgb1128 commented 1 month ago

3rd bullet "Class ATE (Testing) – As discussed previously, functional testing of SFR claims may or may not be different when the TOE is evaluated in the cloud. For cases where on-premise and cloud evaluation of a given SFR may differ, the PP author is expected to provide clear guidance as to the evaluation activities that are different for each use case."

From a CB perspective it is important to clearly define the complete stack of the cloud on which was tested. For example: "This might include: Explicitly stating on which version of the CSP the TOE was tested on and including, as detailed as applicable, the cloud composition stack of the Trusted Platform. This might include, if applicable, regions, data centers, hardware machine pools, servers, virtualization manager, operating system, CPUs used, ..."

bharveyTX commented 3 weeks ago

To add some extra details on test configuration.