commoncriteria / application

Protection Profile for Application Software
The Unlicense
9 stars 3 forks source link

add additional permissions (e.g. send/recv SMS, phone calls) to FDP_DEC_EXT.1.1 #42

Closed jeffblank closed 10 years ago

jeffblank commented 10 years ago

These should be added to the assurance activity for android, as well as discussion about the general set of android permissions that are gathered.

zsmi commented 10 years ago

Hopefully I have fixed this the way you wanted. If not I can reopen the ticket.

jeffblank commented 10 years ago

It's not bad, but please see if you can separate out the sensitive info repos and hardware resources (FDP_DEC_EXT.1.1 http://common-criteria.rhcloud.com/application/output/application.html#FDP_DEC_EXT.1.1 and FDP_DEC_EXT.1. http://common-criteria.rhcloud.com/application/output/application.html#FDP_DEC_EXT.1.12), and maybe include a link to Google documentation about permissions since they control the overall set of permissions for the Android platform. Are there permissions that don't fit into "sensitive info repos" or "hardware resources"? We may need to rework in more generic sense if so, but keeping in mind how other platforms behave. (More simply, in the case of iOS.) Later in the process we will certainly have to negotiate with the CC translators to see if we can get away with any of this, and push right to the edge of them telling us NIAP will positively be banished from CC forever for our naughty use of plain English.

On Mon, Jul 21, 2014 at 12:11 PM, zsmi notifications@github.com wrote:

Hopefully I have fixed this the way you wanted. If not I can reopen the ticket.

— Reply to this email directly or view it on GitHub https://github.com/commoncriteria/application/issues/42#issuecomment-49626930 .