commoncriteria / mobile-device

Protection Profile for Mobile Device Fundamentals
The Unlicense
14 stars 3 forks source link

Use relative numbering for test cases instead of unique numbering #80

Open amasino opened 1 year ago

amasino commented 1 year ago

The approach for numbering test cases in the Protection Profiles vary. In the case of this PP, the test number is unique in the document. For other, the test case number is initialized for each test assurance activity. Is the approach for this PP intended?

I see several drawbacks with this approach:

Adding test cases in technical decisions during the life of the PP would eventually break the sequence.
When the PP is used in conjunction with other PP modules or functional packages, the uniqueness is also broken. Reference to the document will be necessary.
Test cases for not included SFR will not be shown in the Security Target, so there will be holes in the sequence anyhow. Checking the completeness of test cases within each SFR would be more difficult to check.

My suggestion is use numbering relative to each Testing assurance activity. I don't see the benefit of having a continual sequence of test cases in real cases.