RE: wordings are not consistent in CCV3.1
- Subject: RE: wordings are not consistent in CCV3.1
- From: "John Boone" <jboone@ashtonlabs.com>
- Date: Fri, 13 Oct 2006 17:05:02 -0400
- Content-Transfer-Encoding: 7bit
- Content-Type: text/plain; charset="us-ascii"
- In-Reply-To: <200610111026.15360.out@itsef.com>
- Thread-Index: AcbtD6JO2lTK7WBVQiu93U60uNnXXQB+iRCw
Hi,
I'm not jumping in on one side or the other of the wording arguments, but I
thought I could add something that might clarify the (original) need for
this type of phrase in the CC. It might help explain the intended semantics
...
I think these phrases support the concept that a TOE might apply a policy to
a "subset" of objects or subjects. E.g., access control for file system
objects, but not printer buffers. Hence, these SFRs had to qualify
everything, to point to the objects (for instance) that were within scope.
Again, not arguing either side of doing it this way ... and not addressing
the consistency issues ...
-John
[...]
> > CC(V3.1) Part2.
> >
> > 1. "covered by the SFP" --- P57 FDP_ACC.1.1
> > 2. "controlled under the SFP" --- P73 FDP_ITC.1.1
> > 3. "controlled by the SFP(s) --- P76 FDP_ITT.2.2
> > 4. "controlled by the TSF" --- P82 FDP_SDI.1.1
> >
> > Are they all the same?
[...]
Date Index |
Thread Index |
Problems or questions? Contact list-master@nist.gov