biometricITC / cPP-biometrics

Contains the development of a Collaborative Protection Profile for biometrics
MIT License
10 stars 2 forks source link

BMD descriptions #327

Closed woodbe closed 3 years ago

woodbe commented 3 years ago

This is to close #325

Proposed changes for all the current SFRs that could use the BMD.

gfiumara commented 3 years ago

Do we need to be specific about the "details" that should be in the BMD for either PAD or quality? I'm not sure what specifically we could say. Is it sufficient to say something like "this technique employs our trained machine learning model for assessing quality, based on a dataset of 3000 images whose quality labels were applied by certified examiners"?

woodbe commented 3 years ago

@gfiumara so given that we are providing a specific document which would not be publicly released, the expectation is that they will need to provide specific details that could be used to evaluate whether the testing is acceptable. The main point for the BMD notice in the docs is to specify that some level of overview must be provided in the public TSS so that someone who reads the published ST would be able to at least have a high level overview of how the product meets the requirements (or how the testing was done to show it). The BMD description would still have to be enough to actually pass the validator review, and there I would prefer not to get too prescriptive (though we have tried to provide outlines about what is expected).

So really the point of what is said is to specifically state you MUST add something to the TSS, and the rest can go into the BMD, instead of letting the vendor put everything into the BMD.