commoncriteria / mobile-device

Protection Profile for Mobile Device Fundamentals
The Unlicense
14 stars 3 forks source link

Tethering management requirements (FMT_SMF_EXT.1 #25/41) #63

Open woodbe opened 2 years ago

woodbe commented 2 years ago

Management item 41 provides options for controlling tethering, but in many evaluations tethering is also being claimed in item 25 as it is a way where the device acts as a server and can be enabled/disabled. It isn't completely clear (since the requirement lists it as "protocols") whether this is the intent or not, but this is how it has been used in the past. If the intent is specifically to mean things like a service existing over a standard protocol (i.e. a web server, so you could say the protocol would be HTTP), then it would be useful to specify this more clearly so tethering is not listed here (since it wouldn't need to be).

Guidance in the application note would likely be sufficient to handle this since it could note that tethering is not considered a protocol.