commoncriteria / application

Protection Profile for Application Software
The Unlicense
9 stars 3 forks source link

How to write: Use the application #91

Closed kgal closed 6 years ago

kgal commented 9 years ago

We're getting push back on a lot of our "use all operations" or "mimicking normal usage." Would it make more sense to say, "Perform the operations that are described in its user's manual" or "described in its TSS"?

kgal commented 9 years ago

From CGI: Recommend asking the evaluator to formulate a search strategy for the application's operations most likely to result in a code change and have them execute those operations instead. Such an AA is not without precedence and would lead to a less intractable requirement.