commoncriteria / transforms

Repository for various transforms that are common across CC projects.
The Unlicense
1 stars 2 forks source link

mapping module objectives to base-PP threats #61

Open jfisherbah opened 1 year ago

jfisherbah commented 1 year ago

There are situations where the Base-PP defines a threat that is partially mitigated by a TOE objective introduced by a PP-Module. However, when threats are mapped to objectives in the schema, the mapping is done by defining the threat first and then defining the objectives that map to it. This means that there is no means by which a module objective can be mapped back to a Base-PP threat, because that threat is never actually defined as an object in the module.

To support this, some construction for an 'invisible' threat should exist as a way to map objectives in this situation, without the threat itself being displayed in the module.