commoncriteria / commoncriteria/fileencryption

APP -> MDF FCS requirements

Open
#44 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Future Version
Dominant language
Makefile
Stars
2
Forks
3
PR merge metrics
No merged PRs in 30d

Description

The following App requirements should be handled by the following MDF requirements:

APP -> MDF
FCS_CKM.1 -> FCS_CKM.1 & FCS_CKM_EXT.3
FCS_CKM.1/2 -> FCS_CKM_EXT.3 (would require symmetric to be selected)
FCS_RBG_EXT.1 & FCS_RBG_EXT.2 -> FCS_RBG_EXT.1
FCS_STO_EXT.1 -> FCS_STG_EXT.1 & FCS_STG_EXT.2 (though maybe something to more clearly point out the chain may go further than the number of levels here)
FCS_CKM.1/ALGO -> FCS_CKM.1
FCS_CKM.1/3 -> FCS_COP.1/CONDITIONING & FCS_CKM_EXT.6
FCS_CKM.1/1 -> FCS_COP.1/ENCRYPT
FCS_COP.1/2 -> FCS_COP.1/HASH
FCS_COP.1/3 -> FCS_COP.1/SIGN
FCS_COP.1/4 -> FCS_COP.1/KEYHMAC
FCS_HTTPS_EXT.1 -> FCS_HTTPS_EXT.1

FCS_CKM.2 is not clear here, but it doesn't seem like this is likely to be selected in an FE evaluation anyway, so I don't think not having a match in the MDF is a problem.

It seems like all the crypto options should be able to be handled in an FE eval using the MDF as the base, and I don't see that there needs to be too much editing for this in the FE PPM to have this handled (beyond pointers to the proper location)

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the FE PPM content that maps APP requirements to MDF requirements. Review the crypto mappings in the issue, especially the unresolved FCS_CKM.2 case, and confirm where pointers should be added. Done means the applicable mappings are represented in the FE PPM and the treatment of FCS_CKM.2 is explicitly resolved.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.