|
|
||||
PD-0034: Is Intermingling Multiple PPs in One Document Acceptable? |
||||
|
This decision represents a long-term technical decision based on an OD, and may not be the same as the final results of the source OD. With respect to published criteria documentation and scheme documents, it provides suggested guidance on evaluation direction, but is not authoritative. Authoritative decisions are provided through the published criteria documents and published scheme and international interpretations thereof. With respect to published PPs, PDs are authoritative corrections to the PP, based on input from the PP author (if available), that are in force until the publication of the next revision of that PP.
IssueCan a single document contain multiple intermingled PPs (where the requirements of different PPs are interleaved through the document)? What are the implications for such a document, e.g., for referencing each PP, for how many EAL levels each PP may contain, and for evaluating documents that the evaluation team determines is too complex to understand? ResolutionMultiple PPs may be intermingled in a single document. This single document may not be called ``a' PP, though it may describe itself using other terms such as a ``family' or ``set' of PPs. This document must clearly identify all the PPs it contains, and each evaluated PP in this document must be shown (through evaluation) to meet all of the CC's requirements for PPs. For example:
SupportNeither the Common Criteria nor the Common Evaluation Methodology dictates the structure/presentation of a Protection Profile; CC part 1 B.2.1 notes that figure B.1 merely ``should' be used when constructing the PP's structural outline. They do dictate content properties that must be be shown to be evident for each (and every) PP to be considered valid; CC part 1 B.2.1 explicitly states that a PP ``shall' conform to the content requirements of CC part 1 annex B. Whether the targeted specification resides in a single document or resides in a document with other (potentially intermingled) specifications is irrelevant. Of particular concern for intermingled PP requirements is that the PPs must be referenced unambiguously. The APE_INT requirement addresses this. It states:
Note also that the Common Criteria requires that a given PP have zero or one EAL level, and never more than one EAL level. This is suggested in CC part 1 B.2.6(a)(2) and APE_REQ.1.3C, and is made completely clear by the CEM's APE_REQ.1-7, which states that the evaluator shall ``determine that [the PP] includes an EAL ... or appropriately justifies that it does not include an EAL.' Thus, any document that attempts to define a single PP with multiple EAL levels must be recast into several PPs, where each has at most one EAL level. Coexisting, intermingled PPs do introduce some complexities that must be dealt with to show that the APE requirements for each PP are met. It must be easy to determine which information applies to which PP. Note that class APE includes many requirements for coherency, completeness, and consistency; each PP in a document with multiple intermingled PPs must still meet these requirements. Modification History:
References:
Related NIs:
Related CCIMB-INTERPs:
Source OD: 0185 |