biometricITC / cPP-biometrics

Contains the development of a Collaborative Protection Profile for biometrics
MIT License
10 stars 2 forks source link

PADv2 Plan outline #413

Open woodbe opened 1 year ago

woodbe commented 1 year ago

This isn't meant to be the actual document, but to collect notes that can be used for writing the plan/invitation to participate.

woodbe commented 1 year ago

Modalities - fingerprint, face

NOTE: Eye should probably changed to iris to be clear (in our case) since the requirements are not targeted to retinal or peri-ocular.

Attack Potential - Basic-Enhanced is minimum, further will have to be done as we work

We need to set up a process for regular review of the AP calculations in the PAD to see what may need to be changed.

Intro should also note that this is intended to be able to support various government certification requirements for biometrics

Use of GitHub seems to be OK, as long as proper controls on access, though there could be restrictions on what would be able to be published (certain types of tests). NIST has a private hosted GitLab, that may be something to consider depending on restrictions there.

woodbe commented 1 year ago

Tasks to be performed:

woodbe commented 9 months ago

SME calls every 4 weeks starting on the March 19 call. Alternating calls will be "regular" iTC calls to work on other tasks.

https://github.com/biometricITC/Administration/pull/44 needs to be updated to mention repository access is limited to 2 people from one organization. Participation on calls should be restricted to those members, but may allow others as needed.

Timeline: are the recipes going to be "new" or would they be from their existing toolboxes that would be re-purposed? This would have a big impact on the timeline expectations

Attack Potential Calculations: our current tables are based on ISO, which is not default CC. We need to agree on what we should use at the start. Feedback on adjustments that are needed can be provided back to ISO.

Proper fingerprint collection: revisit how we should collect the source fingerprints (scanner or pulled by person from print)