|
|
||||
PD-0019: Allocation of Requirements in a PP to the Environment |
||||
|
This decision represents a long-term technical decision based on an OD, and may not be the same as the final results of the source OD. With respect to published criteria documentation and scheme documents, it provides suggested guidance on evaluation direction, but is not authoritative. Authoritative decisions are provided through the published criteria documents and published scheme and international interpretations thereof. With respect to published PPs, PDs are authoritative corrections to the PP, based on input from the PP author (if available), that are in force until the publication of the next revision of that PP.
IssueCan an ST allocate (fully or partially) functional and/or assurance requirements that are specified in a PP to the environment (i.e., assumptions, IT Environment requirements) and claim conformance to the PP? ResolutionIn order for an ST to claim conformance to a PP, the TOE, specified by the ST, must fully satisfy and conform to the PP's stated TOE security objectives and requirements. SupportThe CC (Part I, C.2.8) is quite clear that the when presenting a claim of PP conformance, the ST author must justify that the PP stated TOE objectives and requirements are satisfied by the ST stated TOE objectives and requirements. The PP claim rationale must describe and justify any differences between the ST stated TOE objectives and requirements and the PP stated TOE objectives and requirements for which conformance is claimed. It is acceptable for the TOE to have additional objectives or more stringent requirements than those contained in the PP. If the TOE were to have a reduced set of objectives or less stringent requirements this would indicate an ST which is claiming partial conformance to a PP and this is clearly not allowed (CC Part I, C.2.8 e)). The CC is also quite clear that only the TOE security requirements can satisfy the TOE objectives, and the security requirements for the IT environment satisfy the objectives for the environment: CC Part I, C.2.6 a) states the following:
CEM work unit ASE_REQ.1-18 states the following:
CEM work unit ASE_REQ.1-19 states the following:
Modification History:
References:
Related NIs:
Related CCIMB-INTERPs:
Source OD: 0138 |