1Copyright © 2013 The Printer Working Group. All rights reserved. MFP Technical Community Vendor F2F 1 Agenda Notes from ICCC Recap of the F2F meeting.

Slides:



Advertisements
Similar presentations
Printer Working Group Face-to-Face Meeting December 8, 2010
Advertisements

BeKnown How-to: Company Profiles & Jobs App for Timeline.
1 Chapter 40 - Physiology and Pathophysiology of Diuretic Action Copyright © 2013 Elsevier Inc. All rights reserved.
Sept 13-15, 2004IHE Interoperability Workshop 1 Integrating the Healthcare Enterprise Post-Processing Workflow Sanjay Jain Co-Chair, Radiology Planning.
Doc.: IEEE /0006r0 Submission March 2005 Steve Shellhammer, Intel CorporationSlide 1 What is a CA document? Notice: This document has been prepared.
My AmeriCorps AmeriCorps National Programs Member Recruitment Presentation developed for the Corporation for National and Community Service by the eGrants.
1 Balloting/Handling Negative Votes September 11, 2006 ASTM Training Session Bob Morgan Brynn Iwanowski.
1 Balloting/Handling Negative Votes September 22 nd and 24 th, 2009 ASTM Virtual Training Session Christine DeJong Joe Koury.
Task Group Chairman and Technical Contact Responsibilities ASTM International Officers Training Workshop September 2012 Scott Orthey and Steve Mawn 1.
OLAC Process and OLAC Protocol: A Guided Tour Gary F. Simons SIL International ___________________________ OLAC Workshop 10 Dec 2002, Philadelphia.
© 2006 Open Grid Forum OGF19 Federated Identity Rule-based data management Wed 11:00 AM Mountain Laurel Thurs 11:00 AM Bellflower.
© 2006 Open Grid Forum INFOD-WG Status and Plans OGF21, Seattle, WA, USA
1 Copyright © 2012 The Printer Working Group. All rights reserved. IPP Working Group Session August 7, 2012 Redmond, WA PWG F2F Meeting.
1Copyright © 2012, Printer Working Group. All rights reserved. PWG Plenary Status Report IDS Working Group August 6, 2012 Redmond, WA PWG F2F Meeting Joe.
1Copyright © 2010, Printer Working Group. All rights reserved. PWG Plenary Status Report IDS Working Group August 4, 2010 Bagsværd, Denmark- PWG F2F Meeting.
1Copyright © 2008, Printer Working Group. All rights reserved. Imaging Device Security (IDS) Working Group Camas, WA - PWG F2F Meeting August 13, 2008.
1 Copyright © 2009, Printer Working Group. All rights reserved. IPP Working Group Session 9 December 2009 Austin, TX - PWG F2F Meeting.
1 Copyright © 2009, Printer Working Group. All rights reserved. 1 IPP Working Group Session 14 October 2009 Cupertino, CA - PWG F2F Meeting.
1Copyright © 2011, Printer Working Group. All rights reserved. PWG Plenary Status Report IDS Working Group February 2, 2011 Wailea-Makena, HI PWG F2F Meeting.
1 Copyright © 2010, Printer Working Group. All rights reserved. IPP Working Group Session 10 February 2010 Scottsdale, AZ - PWG F2F Meeting.
1 Copyright © 2010, Printer Working Group. All rights reserved. IPP Working Group Session 10 February 2010 Scottsdale, AZ - PWG F2F Meeting.
1 Copyright © 2005, Oracle. All rights reserved. Introduction.
The Managing Authority –Keystone of the Control System
NIMAC 2.0: The Accessible Media Producer Portal NIMAC 2.0 for AMPs.
May Welcome and Introductions Training Overview Evolution from CSRS to CEDARS (Fri) Submission and Editing Process (Tues) Course Catalog, Student.
Facebook Part III How to Use the Features of Facebook Patrick Therrien Technology & Education Training Specialist.
Michigan Electronic Grants System Plus
Addition Facts
Module 2 Sessions 10 & 11 Report Writing.
©2011 Quest Software, Inc. All rights reserved.. Andrei Polevoi, Tatiana Golubovich Program Management Group ActiveRoles Add-on Manager Overview.
Managing Government Records Directive ACERA Meeting November 6, 2012 Don Rosen Director of Policy, Analysis and Enforcement Office of the Chief Records.
1. 2 Anyone can suggest an idea for a law. Only Members of Congress can introduce a proposed law to the House or Senate. 3.
Session 2: Introduction to the Quality Criteria. Session Overview Your facilitator, ___________________. [Add details of facilitators background, including.
iStar How to Create an Amendment
Creating a WordPress Website Oklahoma Conference of The UMC Department of Communications 1.
Principles of Information Technology
SPS Nashville 2014 Dynamic Content using SharePoint Search SHAREPOINT SATURDAY NASHVILLE– APRIL 5, 2014 MIKE ORYSZAK BLOG: TWITTER:
National Information Assurance Partnership Paul Mansfield January 2013
Using SD K12 SharePoint®.
1 CS Tutorial 2 Architecture Document Tutorial.
Services Course Windows Live SkyDrive Participant Guide.
Doc.: IEEE OmniRAN-13/0069r0 Submission September 2013 Michael Montemurro, BlackBerrySlide 1 Liaison Report for OmniRAN EC SG Date: Authors:
1 Advanced Archive-It Application Training: Quality Assurance October 17, 2013.
20&27 May Agenda 1.Highlight the difference between system flow of e- Invoice and paper invoice – 15 minutes 2.Demonstrate the operation procedure.
Module 12 WSP quality assurance tool 1. Module 12 WSP quality assurance tool Session structure Introduction About the tool Using the tool Supporting materials.
A lesson approach © 2011 The McGraw-Hill Companies, Inc. All rights reserved. a lesson approach Microsoft® PowerPoint 2010 © 2011 The McGraw-Hill Companies,
© Paradigm Publishing, Inc Excel 2013 Level 2 Unit 2Managing and Integrating Data and the Excel Environment Chapter 6Protecting and Sharing Workbooks.
Registry system data exchange General design requirements Pre-sessional Consultations on Registries 19 October 2002 New Delhi, India UNFCCC secretariat.
South Dakota Library Network MetaLib User Interface South Dakota Library Network 1200 University, Unit 9672 Spearfish, SD © South Dakota.
User Kickoff meeting: ALR Incident Reporting Automation Pilot
© Copyright 2011 John Wiley & Sons, Inc.
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Bangalore, India,17-18 December 2012 Sustainable Broadband Communications: International Perspective – Common Criteria David Martin, Head of International.
Comparison between Family of PPs and PP with Packages Brian Smithson and Ron Nevo.
Moodle (Course Management Systems). Assignments 1 Assignments are a refreshingly simple method for collecting student work. They are a simple and flexible.
Doc.: IEEE Submission March 2004 Tom Siep, TMS ConsultingSlide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs)
Bangalore, India,17-18 December 2012 Sustainable Broadband Communications: International Perspective – Common Criteria David Martin, Head of International.
Copyright (C) 2007, Canon Inc. All rights reserved. P. 0 A Study on the Cryptographic Module Validation in the CC Evaluation from Vendors' point of view.
1 draft-sidr-bgpsec-protocol-05 Open Issues. 2 Overview I received many helpful reviews: Thanks Rob, Sandy, Sean, Randy, and Wes Most issues are minor.
Doc.: IEEE /1623r0 Submission November 2006 Jim Petranovich, Conexant Systems, Inc.Slide 1 PHY Ad Hoc Nov 1 Agenda and Minutes Notice: This document.
Doc.: IEEE /0408r0 Submission May 2005 John Klein, SymbolSlide 1 TPC Comments Notice: This document has been prepared to assist IEEE It.
Minutes Document March 2006 Terry Cole, AMDSlide Editor’s Best Practices Terry Cole, AMD WG Technical Editor & Simon Barber, Devicescape.
Doc.: IEEE Submission November 2012 Robert F. Heile, ZigBee AllianceSlide 1 EC Monday Meeting Report November 12, 2012 Grand Hyatt San.
9 th International Common Criteria Conference Report to IEEE P2600 WG Brian Smithson Ricoh Americas Corporation 10/24/2008.
Editor’s Guideline Version 1.0
9th International Common Criteria Conference Report to IEEE P2600 WG
NesCom PAR Review Period Comment Dialog
Agenda and minutes TGn PHY ad hoc
Agenda and minutes TGn PHY ad hoc
Yesterday’s entertainment
Presentation transcript:

1Copyright © 2013 The Printer Working Group. All rights reserved. MFP Technical Community Vendor F2F 1 Agenda Notes from ICCC Recap of the F2F meeting in Orlando Discussion of currently open issues and proposed resolutions er=descending&text=[issue] er=descending&text=[issue Updates from NIAP and IPA (if any) Plans and schedules Open discussion

Copyright © 2013 The Printer Working Group. All rights reserved. Notes from ICCC (1) The theme was Collaboration Major news items CNSSP #11 published (before ICCC) India elevated to certificate authorizing scheme All CCRA members agree in principle to new CC Recognition Arrangement 2

Copyright © 2013 The Printer Working Group. All rights reserved. Notes from ICCC (2) The CC Users Forum had a very strong presence before and during ICCC Next CCUF-CCDB workshop ~ Istanbul, ~ March Next ICCC was not announced at this ICCC It will be somewhere in India, late September as usual My guess is that ICCC 2015 will be in Australia 3

Copyright © 2013 The Printer Working Group. All rights reserved. Notes from ICCC (3) Some interesting presentations Dag Ströman (CCMC chair and head of the SE scheme) reported on the new CC pilot project creating a USB PP. It has been going on for a long time, and no TC created yet. T-Systems presented How to Create a Slim and Comprehensive PP, a process that looked similar to how we did the IEEE 2600-series PPs (except that it clusters SFRs around TOE security functions). 4

Copyright © 2013 The Printer Working Group. All rights reserved. Notes from ICCC (4) More interesting presentations IPA presented Vulnerability-Centric Assurance Activities for MFP PP as a candidate cPP, which foretells how IPA might write assurance activities in the new MFP PP. IPA also published a major update to their MFP Vulnerabilities research paper, this time in English too! In Japanese: report.pdf report.pdf In English: report_E.pdf report_E.pdf 5

Copyright © 2013 The Printer Working Group. All rights reserved. Notes from ICCC (5) Yet more interesting presentations Exact Conformance was explained by Jim Arnold (but it may or may not match NIAPs official but undocumented definition). Its Just a Printer – Lessons Learned over 10 Years of CC Evaluations by Xerox and CSC, brilliantly presented by Alan Sukert and Lachlan Turner, about how they reduced evaluation cost by 40%. Presentations are published on the web site: Photos and videos will be posted, sometime? 6

Copyright © 2013 The Printer Working Group. All rights reserved. Notes from ICCC (6) CNSSP #11 was published before ICCC I set up a Q&A session with NIAP at the CCUF-CCDB workshop on the Friday before ICCC Janine Pedersen answered questions that were submitted in advance and additional questions from the audience NIAP asked me to not publish a transcript because they want to make an official fact sheet They are working on a fact sheet Its pretty good 7

Copyright © 2013 The Printer Working Group. All rights reserved. Recap of Orlando F2F A full day meeting 17 in-person attendees, 4 people by telecon 7 different vendors from 4 countries 3 different labs, 3 different CC schemes, 3 different consultancies, and 2 others Not much administrative progress IPA and NIAP people were busy with CCRA meetings We addressed 34 technical comments Proposed resolutions for 25 issues Identified steps for further study on the other 9 issues Made vague plans for periodic telecons, F2F meetings 8

Copyright © 2013 The Printer Working Group. All rights reserved. Lots of comments were resolved Some were implemented in draft Some were rejected For details, refer to the MFP TC F2F summary, posted on Teamlab editor.aspx?action=view&fileid= editor.aspx?action=view&fileid=

Copyright © 2013 The Printer Working Group. All rights reserved. Currently open issues (1) User authorization is defined too narrowly Suggest that is too narrow. Need to also include access to data. Note that Para 91 says exactly that, but only about faxes. Proposal: remove the second half of Note that the TOE can receive a PSTN fax without any User authorization, but the received Document is subject to access controls. 10

Copyright © 2013 The Printer Working Group. All rights reserved. Currently open issues (2) Discussion on I&A&A failure including external authentication There was interesting discussion about external I&A&A and what happens when it fails. Same thing for external audit storage. (should there be something like FIA_AFL and FAU_STG.4 for those cases?) TC F2F action item: look at Enterprise Security Management for how they handle this. Maybe it is just put in the audit log. None of the NDPP or ESM PPs address this (see s.aspx?prjID=239468&id= for details) s.aspx?prjID=239468&id= Proposal: don't worry about specifying how to handle failure of either external authentication services or external audit storage services. 11

Copyright © 2013 The Printer Working Group. All rights reserved. Currently open issues (3) Addition to the table 1, i.e. auditable events (4) For Modification to the group… what additional info should be collected? TC F2F action item: Look at Enterprise Security Management to see what they do. NDPP and ESM either dont even audit the event or (in one case) doesnt collect additional information. Details: s.aspx?prjID=239468&id=260163#comments s.aspx?prjID=239468&id=260163#comments Proposal: don't collect any additional information in the MFP PP. 12

Copyright © 2013 The Printer Working Group. All rights reserved. Currently open issues (4) Term non-fax data for information flow control SFR In FDP_IFF.1 the term non-fax data was confusing to all. Need a new term, or make an ECD. (¶173 and elsewhere) TC F2F action item: One proposal is to use D.USER.DOC and D.USER.JOB as the attributes: In FDP_IFF.1.5 say anything other than that is denied In FDP_IFF.1.2, FDP_IFF.1.3, FDP_IFF.1.4, express the rules for allowing it (left up to the ST author) The other proposal is to create an Extended Component. The TC needs to discuss / decide. 13

Copyright © 2013 The Printer Working Group. All rights reserved. Currently open issues (5) Addition to the table 1, i.e. auditable events (1 & 2) 1. Add Job submission with additional info type and identifier 2. Add to Job completion the additional info identifier and completion status TC F2F action item: vendors need to see if this is a standard practice in existing logs. The security-relevant purpose of this was not clear. Also, we need an answer about adding audit events beyond the PP requirements – does that violate exact compliance? 14

Copyright © 2013 The Printer Working Group. All rights reserved. Currently open issues (6) Audit log specification proposed by PWG PWG has created an audit log spec. We should look at that for potentially important events to log. Also look at the NDPP log requirements. (Table 1) TC F2F recommendation: We are not looking for additional audit requirements for certification purposes (nor format requirements for interoperability). Instead, we should look at the Enterprise Security Management PPs (including draft updates) and NDPP (including errata) for crypto, communications, and log requirements. It was noted that the audit requirements from NIAP and IPA may change over time, so we will need to re-check. 15

Copyright © 2013 The Printer Working Group. All rights reserved. Currently open issues (7) Not sure that these OSPs are necessary [very lengthy comment from Mario about OSPs] 16

Copyright © 2013 The Printer Working Group. All rights reserved. Updates from NIAP and IPA Nothing! 17

Copyright © 2013 The Printer Working Group. All rights reserved. Plans and Schedules NIAP updated their PP development schedule page and they show the MFP PP completion in Q

Copyright © 2013 The Printer Working Group. All rights reserved. Open Discussion 19