commoncriteria / application

Protection Profile for Application Software
The Unlicense
9 stars 3 forks source link

(Sensitive) Data #77

Closed WeeknightMVP closed 9 years ago

WeeknightMVP commented 9 years ago

OK, I'll ask here for posterity: Why must we explicitly mention the option of encrypting all data as one option for meeting the objective to encrypt sensitive data per our security/privacy concerns? I understand that certain factions may elect to implement additive security measures for multiple layers of information requiring varying degrees of protection, but why is this our concern? Why can't we simply note that if an application encrypts all data, then it indeed encrypts all sensitive data?

logic101