suit-wg / information-model

1 stars 1 forks source link

Incorporate review feedback & e2e security justification #4

Closed bremoran closed 4 years ago

bremoran commented 4 years ago

This change set includes editorial fixes from review and several threats and security requirements that are necessary to justify the requirement for an End-to-End security model in SUIT.

The new threats listed are:

These were omitted from the previous Information Model drafts because they do not directly inform the fields present in the manifest, so they were not directly relevant to the SUIT manifest. However, references to End-to-End security imply some system architecture which requires a firm justification. These threats have been added to explain why an End-to-End security model is needed.

The new security requirements are:

These requirements address the Author side of the End-to-End security model