NIAP: View Technical Decision Details
NIAP/CCEVS
  NIAP  »»  Protection Profiles  »»  Technical Decisions  »»  View Details  
TD0822:  Correction to Windows Manifest File for FDP_DEC_EXT.1

Publication Date
2024.04.10

Protection Profiles
PP_APP_v1.4

Other References
FDP_DEC_EXT.1.1, FDP_DEC_EXT.1.2

Issue Description

The Windows tests for FDP_DEC_EXT.1 refer to the WMAppManifest.xml file, but this is an outdated name and Windows now uses the AppxManifest.xml file.

Resolution

The Microsoft Windows test for FDP_DEC_EXT.1.1 in PP_APP_V1.4 is modified as follows, with green-highlighted underlines indicating additions and red-highlighted strikethroughs indicating deletions:

 

For Windows Universal Applications the evaluator shall check the WMAppxManifest.xml file for a list of required hardware capabilities. The evaluator shall verify that the user is made aware of the required hardware capabilities when the application is first installed. This includes permissions such as ID_CAP_ISV_CAMERA, ID_CAP_LOCATION, ID_CAP_NETWORKING, ID_CAP_MICROPHONE, ID_CAP_PROXIMITY and so on. A complete list of Windows App permissions can be found at:

For Windows Desktop Applications the evaluator shall identify in either the application software or its documentation the list of the required hardware resources.

 

 

The Microsoft Windows test for FDP_DEC_EXT.1.2 is modified as follows, with green-highlighted underlines indicating additions and red-highlighted strikethroughs indicating deletions:

 

For Windows Universal Applications the evaluator shall check the WMAppxManifest.xml file for a list of required capabilities. The evaluator shall identify the required information repositories when the application is first installed. This includes permissions such as ID_CAP_CONTACTS, ID_CAP_APPOINTMENTS, ID_CAP_MEDIALIB and so on. A complete list of Windows App permissions can be found at:

For Windows Desktop Applications the evaluator shall identify in either the application software or its documentation the list of sensitive information repositories it accesses.

Justification

See Issue Description.

 
 
Site Map              Contact Us              Home