appswcpp / repository

MIT License
10 stars 2 forks source link

[cPP CHANGE] Selection-based SFRs in FIA family without selection trigger. #149

Open OlegAndrianov opened 3 months ago

OlegAndrianov commented 3 months ago

What is the change request for the cPP? Please describe. Base cPP, version 1.0e Section B2. "This section defines selection based Identification and Authentication requirements that underlie other security properties of the TOE" But FIA_AFL.1.1, FIA_EIP_EXT.1, FIA_UIA_EXT.1, FIA_UAU_EXT.2, FIA_UAU.7 do not contain a clarification on then those need to be selected for the ST. Mandatory SFRs does not seem to contain any trigger that draws them in. The answer probably lies in the FIA_UAU_EXT.5 User Authentication Mechanisms (hence the dev note in it I suppose), that contains a selection guidance.

Describe the solution you'd like I propose moving FIA_UAU_EXT.5 User Authentication Mechanisms to optional requirements section.

Describe alternatives you've considered Moving FIA_UAU_EXT.5 User Authentication Mechanisms to Mandatory requirements section is possible but that would probably require modification of the SFR to include additional selection options like "rely on platform" and "do not support"