Open-Credentialing-Initiative / Digital-Wallet-Conformance-Criteria

Conformance Criteria for Digital Wallets | https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
Apache License 2.0
1 stars 2 forks source link

NFR009 - Audit Requirements: difference to NFR003 and NFR010? #43

Closed bluesteens closed 1 year ago

bluesteens commented 1 year ago

for Steering

Both NFR talk about user actions as well as transaction logs. I believe the intention of NFR003 was to deal with user action logs and NFR009 to address tx logs.

I suggest we make that distinction clear by removing any cross-over language.

In addition, NFR010 also talks about data logs and storage. Can we combine 10 and 09?

related issue: https://github.com/Open-Credentialing-Initiative/Digital-Wallet-Conformance-Criteria/issues/13


Affected Parties (help determine Sunrise/Sunset):

Affected OCI Artifact

Change Category (Guides Steering Review)

- Steering/Industry Review

- Steering/Industry Notification

bluesteens commented 1 year ago

003: "The solution SHOULD also record important actions performed by registered users." >> SHALL 009: purpose is granularity of records. records available for inspection (not just transfer), word as "SHALL have capability" "keep detailed records" 010: purpose is storage of records. re-establish, word as "SHALL have capability". The Wallet Provider SHALL be capable of transferring or making available such records to the user. "... to enable user to comply with regulatory data storage requirements"

bluesteens commented 1 year ago

review 06/22/23: 003 The system collects evidence of user actions to prove the origin and authenticity of data in the event of a future dispute.

remove "important", activities = actions

remove "initiating"

are = made

009 accept all EW sugg except Measurement

010 accept EW