Create Section 508 VPAT (Voluntary Product Accessibility Template) for Npcap
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 3.6k
- Forks
- 592
- PR merge metrics
- No merged PRs in 30d
Description
Even though the Npcap driver and library doesn't have much user interface to speak of, we receive occasional requests for a VPAT (Voluntary Product Accessibility Template) for Npcap. This especially comes from U.S. Government buyers and users who may be required by legislation to consider the level of conformance to Section 508 accessibility guidelines as part of their procurement process. A VPAT allows them to more easily understand the level of conformance. The ITI publishes three versions of the official VPAT template -- a Section 508 one for the U.S. Federal accessibility standard, an "EU" one for European Union's accessibility requirements, and a WCAG one for Web Content Accessibility Guidelines. You can also do a VPAT 2.4 INT incorporating all three. Our initial priority should probably just be VPAT 2.4 508 because I haven't received any requests for the others. Even the requests for the 508 one are only a handful per year, but it still might be worthwhile to obtain depending on the cost and effort.
An important thing to note is that Npcap barely has a user interface, so one would expect (hope) that this would be a lot easier than with normal software. Npcap OEM is usually installed silently as a component of other software and then works behind the scenes to process packets. The end user generally does not interact with Npcap itself. With the free/demo version of Npcap, user interaction is generally limited to downloading Npcap from the web site and running the installer (which should be just as accessible as any other NSIS installer). Users might also read the documentation online, though I don't know whether that counts for VPAT purposes.
I haven't investigated this thoroughly yet, so I'm also not sure whether this is something we can do once and then fairly easily apply to later versions of Npcap, or whether each version would require a time-consuming new certification. I'm also not sure whether we need to do both Npcap OEM and free/demo Npcap. If we have to pay for this certification work and it only covers one of them, we should do Npcap OEM of course. We could still make the VPAT public for free users with a note that the actual content should be generally applicable to the free/demo version as well.
There are some companies which specialize in VPAT creation that we could obtain quotes from. For example a quick web search shows the Level Access offering and also Deque's offerings. Those pages have more useful information on the process too.
Or maybe there is similar driver (no user interface) software which has already gone through this process and for which we could (with permission) basically copy their VPAT and audit results?
I haven't solicited quotes yet as I'm still in the process of understanding this process and whether it's something we actually need. Requests have been fairly rare, but they have come from real potential customers. It's not clear whether anyone has ever decided NOT to buy or use Npcap based on the lack of a VPAT.
I'm opening this as a public issue (instead of just my private tasklist) just in case anyone has comments about VPAT. Examples of useful information we'd appreciate include:
- Would an Npcap VPAT be useful to you or your organization? Please include any reasoning and details about what you need.
- If you've been involved in the creation of any VPATs for other products, we'd appreciate any insights or notes that might help us in the process.
- If you've hired anyone to help create a VPAT, we'd love to hear who they are and about your experience with them. Feel free to email me directly (gordon at nmap.org) if you don't want to post it publicly.
- If you know of any VPAT's for products similar to Npcap (especially Windows driver or library software without much in the way of a user interface), please post a link or let me know who I can talk to about it.
We also receive occasional requests for Nmap and/or Zenmap VPAT's, but I think we'll deal with Npcap first because it should be a much simpler case. One large U.S. Government Agency told me in Feb 2020 that they were "looking to the possibility of creating of an End-user VPAT for internal use" for Nmap. They were not an Nmap OEM customer but were using the normal free Nmap. I could follow up and ask whether they created it and whether they would send me a copy.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the ITI VPAT templates and the Level Access and Deque process information linked in the issue. Determine whether Npcap OEM, free/demo Npcap, or both should be covered, whether the work requires recurring certification, and what evidence or vendor quotes would be needed; done means producing an agreed VPAT scope or documented recommendation.
Written by the indexing model from the issue text.
Assessment
- Domain
- accessibility, documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100