Skip to content
jeffblank edited this page May 22, 2015 · 17 revisions

Brainstorming Area for XML Schema

Top-level requirements

  • The elements of the schema must be sufficient to capture the information.
  • A stylesheet will need to be developed alongside the schema, to demonstrate at least one style of reciprocity report. Different organizations may customize the stylesheet to meet their needs, but a common schema is necessary to capture the essential data.
  • Each general area of the schema should correspond to Requirements for Vetting Mobile Apps from the Protection Profile for Application Software. If there is security-relevant reporting that is not contained in the Protection Profile, then the Protection Profile should be revised appropriately. The schema can be revised ahead of the Protection Profile.
  • Mobile app vetting tool vendors must be able to validate their output against the schema.

Essential Elements

The list below represents a working draft of items to include in the schema. It leverages the excellent Sample Mobile App Security Vetting Reciprocity Report provided in the Proposed Concept of Operations Supporting Reciprocity (22 Dec 2014). This wiki representation should translate into a formal XML schema.

garbagehttps://www.niap-ccevs.org/pp/pp_app_v1.1_table-reqs.htm#FTP_DIT_EXT.1.1

Clone this wiki locally