commoncriteria / application

Protection Profile for Application Software
The Unlicense
9 stars 3 forks source link

should SWID be mandatory now? #175

Open jfisherbah opened 1 year ago

jfisherbah commented 1 year ago

App PP v1.4 has an app note in FPT_IDV_EXT.1 that says SWID tags will be required in "the next major release" of the PP. Based on this, we should consider whether that is still applicable and, if so, should update the SFR accordingly. Since I haven't heard anything either way, I wanted to check.

mbdowne commented 9 months ago

Yes, this should be mandatory.

jfisherbah commented 9 months ago

With a selectable "assignment: other" in addition to the mandatory SWID? Or should the SWID be the sole source of version information?

mbdowne commented 9 months ago

Sole source, assignment and selection should all be removed.

jfisherbah commented 9 months ago

SFR updated for SWID tags to be the only acceptable version information. The extended component definition of the SFR remains the same,

i.e. the ECD specifies that application versioning can be done through SWID or through some other measure, and then the body text definition of the SFR forces the ST author to choose only the "SWID" option.