commoncriteria / application

Protection Profile for Application Software
The Unlicense
9 stars 3 forks source link

New CC:2022 SFRs for RBG - should be reviewed #188

Open jfisherbah opened 1 month ago

jfisherbah commented 1 month ago

FCS_RBG_EXT.2 was replaced in this version of the PP because random bit generation requirements got added to CC:2022 Part 2. Specifically, the new requirements are as follows:

Based on selections made in FCS_RBG.1, any of FCS_RBG.2, FCS_RBG.3, or (FCS_RBG.4 AND FCS_RBG.5) are included. This also required the addition of FPT_TST.1 and FPT_FLS.1 because they are dependencies of FCS_RBG.1.

Special attention to the review of this material is requested.

jfisherbah commented 1 month ago

Additionally note that FCS_RBG.1 adds a new element (FCS_RBG.1.3) for reseeding which was not previously included. Uncertain whether specific selections should be prohibited/mandated or what level of evaluation activity is sufficient for these claims.