commoncriteria / commoncriteria/transforms
mapping module objectives to base-PP threats
Nobody has claimed this yet.
- Dominant language
- XSLT
- Stars
- 1
- Forks
- 4
- PR merge metrics
- No merged PRs in 30d
Description
There are situations where the Base-PP defines a threat that is partially mitigated by a TOE objective introduced by a PP-Module. However, when threats are mapped to objectives in the schema, the mapping is done by defining the threat first and then defining the objectives that map to it. This means that there is no means by which a module objective can be mapped back to a Base-PP threat, because that threat is never actually defined as an object in the module.
To support this, some construction for an 'invisible' threat should exist as a way to map objectives in this situation, without the threat itself being displayed in the module.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing how the schema defines threats and maps objectives, focusing on the ordering described in the issue. Determine how a PP-Module objective can reference a Base-PP threat without defining or displaying that threat in the module. Done means the mapping is supported while the inherited threat remains invisible.
Written by the indexing model from the issue text.
Assessment
- Domain
- tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100