-
Notifications
You must be signed in to change notification settings - Fork 4
Schema
jeffblank edited this page May 22, 2015
·
17 revisions
- The elements of the schema must be sufficient to produce a reciprocity report.
- A stylesheet will need to be developed alongside the schema, to demonstrate at least one style of reciprocity report. Different organizations may customize the stylesheet to meet their needs, but a common schema is necessary.
- Each general area of the schema must correspond to Requirements for Vetting Mobile Apps from the Protection Profile for Application Software.
- Mobile app vetting tool vendors must be able to validate their output against the schema.
The list below represents a working draft of items to include in the schema. It leverages the excellent Sample Mobile App Security Vetting Reciprocity Report provided in the Proposed Concept of Operations Supporting Reciprocity (22 Dec 2014). This wiki representation should translate directly into a formal XML schema.
-
FCS_RBG_EXT.1.1use of any random bit generators
- attribute: parameters and API used
-
FCS_STO_EXT.1.1 list of any credentials stored/used
- attribute: where they are stored
- FDP_DEC_EXT.1.1 list of hardware resources used
- FDP_DEC_EXT.1.2 list of sensitive information repositories