biometricITC / Administration

iTC administration Documentation
0 stars 0 forks source link

Explicit new modality expectations #39

Closed woodbe closed 3 years ago

woodbe commented 3 years ago

Looking at some of the NIAP issues, one in particular pointed to not allowing a vendor to just "add" a modality. That isn't something that is allowed (and a PR has been made to remove that option), but it also made me think that we don't have an explicit process for what we want to add a new modality.

We did this in part for the toolbox, but that is narrowly focused specifically on the toolbox, not on expectations or requirements to add this to the PP-Module (and possibly the SD if needed) in addition.

What I'm thinking is that we need to create a new document, along the lines of https://github.com/biometricITC/Administration/blob/master/Toolbox_Updates.adoc that has the expectations for creating a new modality (largely taken from the last row), and then to update this document to point to the new modality document for the question of adding a new toolbox (assuming it is a new toolbox for a new modality).

Related to this, I realized that there was also an intent to create some Issue choices related to this which haven't been done (I realized it because I clicked on the link and they aren't there). The question is where do we want to new Issues for new modalities (toolbox requests are clearly part of the toolbox).

gfiumara commented 3 years ago

It looks like you may have started new modality issue templates in cPP-toolboxes? I think that's a good place to track them, but realizing that making a new modality is a larger process, I'd think that after the initial determination that a new modality is needed, the first step would be to create a new repository for that modality's toolbox and then create smaller issues toward creating the toolbox within that repository.

woodbe commented 3 years ago

So looking at it more closely, I'm wondering if just tweaking the toolbox update will be sufficient for this. Basically change the last row to be "add a new modality" and not "add a new toolbox for a new modality" and then add some additional pieces about justifying the reason for adding the new modality (use in market or something) as part of what they need to provide may be enough.

Thoughts?