biometricITC / cPP-biometrics

Contains the development of a Collaborative Protection Profile for biometrics
MIT License
10 stars 2 forks source link

FIA_MBE_EXT.1.1 is not scoped #395

Closed chapman-s closed 1 year ago

chapman-s commented 2 years ago

What is the change request for the cPP/PP-module? Please describe.

For FIA_MBE_EXT.1.1, the actual requirement is not scoped and, technically, could apply to any type of enrollment on the TOE. When the current SFR appears in the context of an MDF PP ST containing 130 SFRs including other enrollment types (e.g., MDM agent enrollment), it’s not immediately clear what FIA_MBE_EXT.1.1 applies to. (Note that the title of an SFR is not a valid SFR scoping mechanism in CC.)

Describe the solution you'd like

Consider enhancing the FIA_MBE_EXT.1.1 wording by limiting the scope of the SFR to just the biometric system. For example:

FIA_MBE_EXT.1.1 The TSF shall provide a mechanism to enrol an authenticated user to the biometric system.

Describe alternatives you've considered

The ST author will have to refine the SFR for the SFR to make sense in the context of an ST.

Additional context

chapman-s commented 2 years ago

This issue is against the published v1.1.