"The evaluator shall examine the statement of security requirements to determine that it is internally consistent."
There is no proper place to put this so I am putting this here. FCS_TLSS_EXT.1.1 has a mandatory ciphersuite that has been made optional in subsequent versions of the NDcPP. Unless there is a specific reason for it to be required here - it should probably be made optional.
(Mandatory Ciphersuites: o TLS_RSA_WITH_AES_128_CBC_SHA as defined in RFC 3268).
"The evaluator shall examine the statement of security requirements to determine that it is internally consistent."
There is no proper place to put this so I am putting this here. FCS_TLSS_EXT.1.1 has a mandatory ciphersuite that has been made optional in subsequent versions of the NDcPP. Unless there is a specific reason for it to be required here - it should probably be made optional. (Mandatory Ciphersuites: o TLS_RSA_WITH_AES_128_CBC_SHA as defined in RFC 3268).