[Public Interpretations Database]

I-0426: Content Of PP Claims Rationale


TYPE:                 NIAP Interpretation
NUMBER:               I-0426
STATUS:               Approved, Acceptable to CCIMB, CCIMB Interpretation
                      Pending

TITLE:                Content Of PP Claims Rationale
SUPERSEDES:
     I-0383           Content Of PP Claims Rationale

EFFECTIVE:            2000-12-05

SOURCE REFERENCE:     CC v2.1 Part 1 Subclause C.2.9
                      CC v2.1 Part 3 Subclause 5.5 ASE_PPC
RELATED TO:
     I-0383           Content Of PP Claims Rationale
CCIMB ENTRY:          CCIMB-INTERP-0114

ISSUE:

Currently, Common Criteria Part 1 Annex C and Part 3 component ASE_PPC.1 are not consistent with respect to specification of PP Claims Rationale.

STATEMENT

The Part 1 Section C.2.9 "d)" specification of the PP Claims Rationale provides a more complete list of requirements than is found in the ASE_PPC elements in Part 3.

RECOMMENDED CRITERIA CHANGES

[Note: The changes stated below are ADVISORY ONLY, and represent one approach to addressing the guidance in the statement. Other approaches that achieve the same goal are acceptable.]

To address this interpretation, the following changes are made to CC v2.1, Part 3:

  • ASE_PPC.1 is relabeled as ASE_PPC.1-NIAP-0426. Unless otherwise noted in these changes, all normative and informative material associated with ASE_PPC.1 is incorporated unchanged into ASE_PPC.1-NIAP-0426, and all references to ASE_PPC.1 in the CC, CEM, or other Common Criteria documentation is changed to refer to ASE_PPC.1-NIAP-0426.

  • A new Content and Presentation of Evidence element is added to the ASE_PPC.1-NIAP-0426 component:

    ASE_PPC.1.NIAP-0426-1C: The PP Claims Rationale shall explain any difference between the ST security objectives and requirements and those of any PP to which conformance is claimed.

FURTHER CONSIDERATIONS:

Corresponding methodology changes are needed to address this new Content and Presentation of Evidence element.

SUPPORT:

This interpretation addresses an omission in the Common Criteria. Part 1 Section C.2.9 "d)" specifies the required content for the PP claims rationale, but this was not captured in Part 3.

Note: This interpretation is superseding a previously-approved formal interpretation primarily to reflect modifications to the interpretation format. The intent of the interpretation has not been changed, although some specifics of the criteria changes or the support may have been clarified or corrected.

2003-07: This was reviewed by the CCIMB, who issued the following statement:

The CCIMB agrees with the intent of the national interpretation but disagrees with the solution provided. The CCIMB believes that the national interpretation captures the basis of the general notion intended by a statement of compliance.

It is agreed that Part 1 Section C.2.9 "d)" specification of the PP Claims Rationale provides a more complete list of requirements than is found in the ASE_PPC elements in Part 3. It was the intent in CC v2.1 that the statement of objectives in STs claiming compliance to PPs should be consistent with the statement of objectives in the PP. However, this was not captured in the criteria of CC v2.1 Part 3.

The implications of this issue are further reaching than identified in this Request for Interpretation, as the statement of the environment should also be considered in PP compliance. The full issues surrounding this matter will be addressed in the interpretation for RI-215.