Open-Credentialing-Initiative / Digital-Wallet-Conformance-Criteria

Conformance Criteria for Digital Wallets | https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
Apache License 2.0
1 stars 2 forks source link

NFR003 - Security - Non-repudiation: unclear wording #41

Closed bluesteens closed 1 year ago

bluesteens commented 1 year ago

for Steering

NFR003 contains a mix of SHALL and SHOULD that makes it unclear whether the auditability and logging are obligations or -good-to-haves. suggest determining OCI's intention and reword accordingly.


wording:

Solution SHOULD implement an audit trail including non-repudiable digital signatures for all ATP Credential transactions realized on the system. User authentication and activities SHALL be logged. Audit trail SHALL be available for user inspection.


Triage:

Affected Parties (help determine Sunrise/Sunset):

Affected OCI Artifact

Change Category (Guides Steering Review)

- Steering/Industry Review

- Steering/Industry Notification

Communication

bluesteens commented 1 year ago

already addressed by https://github.com/Open-Credentialing-Initiative/Digital-Wallet-Conformance-Criteria/issues/43