Commit c897cc28 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Clause 6: Replace "list of" with "description of"

Allow a more compact form of recording interfaces, fields, test
inputs, etc.
parent a780ea11
Loading
Loading
Loading
Loading
+10 −10
Original line number Diff line number Diff line
@@ -1718,7 +1718,7 @@ Otherwise FAIL
* Documented vulnerability handling policy
* Product SBOM, if applicable
* Product HBOM, if applicable
* List of testing tools used or manual test plan
* Description of testing tools used or manual test plan
* Test reports/scan results
* Sufficiency analysis of analysis of any detected vulnerabilities for false positives, elapsed time exceptions, or documented mitigations

@@ -1763,9 +1763,9 @@ Otherwise FAIL

* Documentation of and rationale for search process for interfaces
* Logs of searches for interfaces
* List of identified interfaces
* Description of identified interfaces
* Sufficiency analysis of rationale for interface search process
* List of methods for protecting or disabling interfaces
* Description of methods for protecting or disabling interfaces
* Logs or records of protecting or disabling interfaces
* Logs or records of attempts to access interfaces
* Sufficiency analysis of documentation of necessity for exposing interfaces for backward compatibility, if any
@@ -2248,10 +2248,10 @@ Otherwise FAIL

#### 6.11.2.5 Evidence

* List of identified interfaces
* List of methods for identifying interfaces
* Description of identified interfaces
* Description of methods for identifying interfaces
* Sufficiency analaysis of methods for identifying interfaces
* List of identified inputs
* Description of identified inputs
* Packet captures or other appropriate logs of the data transmitted
* Sufficiency analysis of analysis of amount of data in response

@@ -2285,7 +2285,7 @@ Otherwise FAIL

* Documentation of and rationale for search process for interfaces
* Logs of searches for interfaces
* List of identified interfaces
* Description of identified interfaces
* Sufficiency analysis of rationale for interface search process
* Analysis of necessity of and alternatives to each identified interface
* Sufficiency analysis of necessity analysis for identified exposed interfaces
@@ -2339,7 +2339,7 @@ Otherwise FAIL

#### 6.14.2.5 Evidence

* List of identified events
* Description of identified events
* Method of triggering events
* Logs of triggering events
* Logs of internal event records and/or host notifications
@@ -2393,7 +2393,7 @@ Otherwise FAIL

#### 6.15.2.5 Evidence

* List of each type of user data or setting written
* Description of each type of user data or setting written
* For each type, record of original value, written value, and value after deletion and reset to secure-by-default method
* Comparison and analysis of different values
* Sufficiency analysis of comparison
@@ -2429,7 +2429,7 @@ Otherwise FAIL

#### 6.15.3.5 Evidence

* List of each type of user data or setting written
* Description of each type of user data or setting written
* For each type, record of original value, written value, and read value
* Comparison and analysis of values
* Sufficiency analysis of comparison