NIAP: View Technical Decision Details
NIAP/CCEVS
  NIAP  »»  Protection Profiles  »»  Technical Decisions  »»  View Details  
Archived TD0465:  Configuration Storage for .NET Apps

Publication Date
2019.11.08

Protection Profiles
PP_APP_v1.3

Other References
FMT_MEC_EXT.1

Issue Description

For Windows applications, the Evaluation Activity for FMT_MEC_EXT.1 specifies namespaces for storing application-specific settings. These namespaces do not account for .NET applications which commonly store application data with the executable.

Resolution

The Evaluation Activity for WIndows for FMT_MEC_EXT.1 shall be modified as follows, with underlines indicating additions:

For Windows: The evaluator shall determine and verify that Windows Universal Applications use either the Windows.UI.ApplicationSettings namespace or the IsolatedStorageSettings namespace for storing application specific settings. For .NET applications, the evaluator shall determine and verify that the application uses one of the locations listed in https://docs.microsoft.com/en-us/dotnet/framework/configure-apps/ for storing application specific settings. For Classic Desktop applications, the evaluator shall run the application while monitoring it with the SysInternals tool ProcMon and make changes to its configuration. The evaluator shall verify that ProcMon logs show corresponding changes to the the Windows Registry or C:\ProgramData\ directory.

Justification

See issue description.

 
 
Site Map              Contact Us              Home