|
|
||||
PD-0075: Identification of Interfaces in HLD |
||||
|
This decision represents a long-term technical decision based on an OD, and may not be the same as the final results of the source OD. With respect to published criteria documentation and scheme documents, it provides suggested guidance on evaluation direction, but is not authoritative. Authoritative decisions are provided through the published criteria documents and published scheme and international interpretations thereof. With respect to published PPs, PDs are authoritative corrections to the PP, based on input from the PP author (if available), that are in force until the publication of the next revision of that PP.
IssueThe Common Criteria requirement for ADV_HLD.1.6C states "The high-level design shall identify all interfaces to the subsystems of the TSF." The CEM (EAL2:ADV_HLD.1, paragraph 727) interprets that (for EAL2) to mean "The high-level design shall include, for each subsystem, the name of each of its entry points." ResolutionAt EAL2 (i.e. ADV_HLD.1), the high-level design identifies the TSF internal structure (in terms of subsystems), and shows the relationships and flow of information between the subsystems. It need only characterize such information flow; it need not specify entry points, parameters, etc. SupportGiven the original intent, and general desire for EAL3 to be roughly equivalent to the TCSEC C2 class, most would agree that the extra level of abstraction that ADV_HLD requires well exceeds the earlier C2 requirements, especially when one considers the implications of the correspondence requirements of ADV_RCR. The additional burden of specifically identifying and naming each interface for each of the subsystems is especially onerous, and far exceeds the amount of evidence that is reasonable for EAL2. Modification History:
References:
Related NIs:
Related CCIMB-INTERPs:
Source OD: 0150 |