ADV_SPM.2 Semiformal TOE security policy model
Dependencies:
ADV_FSP.1 Informal functional specification
Developer action elements:
ADV_SPM.2.1D The developer shall provide a TSP model.
ADV_SPM.2.2D The developer shall demonstrate correspondence between the functional specification and the TSP model.
Content and presentation of evidence elements:
ADV_SPM.2.1C The TSP model shall be semiformal.
ADV_SPM.2.2C The TSP model shall describe the rules and characteristics of all policies of the TSP that can be modeled.
ADV_SPM.2.3C The TSP model shall include a rationale that demonstrates that it is consistent and complete with respect to all policies of the TSP that can be modeled.
ADV_SPM.2.4C The demonstration of correspondence between the TSP model and the functional specification shall show that all of the security functions in the functional specification are consistent and complete with respect to the TSP model.
ADV_SPM.2.5C Where the functional specification is at least semiformal, the demonstration of correspondence between the TSP model and the functional specification shall be semiformal.
Evaluator action elements:
ADV_SPM.2.1E The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence.