Skip to content

Commit 7024c16

Browse files
author
Jenn Honkofsky
committed
Remove modified rationales
1 parent a9671ef commit 7024c16

File tree

1 file changed

+3
-21
lines changed

1 file changed

+3
-21
lines changed

input/PSD-AO.xml

Lines changed: 3 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -173,22 +173,15 @@
173173
<threat name="T.AUDIO_REVERSED">
174174
<description>A malicious agent could re-purpose an authorized audio output peripheral device by converting it to a
175175
low‐gain microphone to eavesdrop on the surrounding audio or transfer data across an air‐gap
176-
through audio signaling.</description>
177-
<addressed-by>FDP_APC_EXT.1 (Modified)</addressed-by><rationale>Mitigates this threat by
178-
ensuring no data or electrical signals can flow between connections and only user-selected
179-
interfaces can rout data.</rationale>
176+
through audio signaling.</description>
180177
<addressed-by>FDP_AFL_EXT.1</addressed-by><rationale>Mitigates this threat by ensuring
181178
outgoing audio signals are within the range of human hearing.</rationale>
182179
<addressed-by>FDP_UDF_EXT.1/AO</addressed-by><rationale>Mitigates this threat by ensuring
183180
output data transit unidirectionally between interfaces.</rationale>
184181
</threat>
185182

186183
<threat name="T.DATA_LEAK">
187-
<from base="bpp-psd"/>
188-
<addressed-by>FDP_APC_EXT.1 (Modified)</addressed-by><rationale>Mitigates this threat by
189-
requiring restrictions on how data is routed between interfaces.</rationale>
190-
<addressed-by>FDP_PDC_EXT.1 (Modified)</addressed-by><rationale>Mitigates this threat by
191-
requiring connections to be only from an authorized list of peripheral devices.</rationale>
184+
<from base="bpp-psd"/>
192185
<addressed-by>FDP_AFL_EXT.1</addressed-by><rationale>Mitigates this threat by ensuring
193186
signals are filtered within the range of human hearing.</rationale>
194187
<addressed-by>FDP_UDF_EXT.1/AO</addressed-by><rationale>Mitigates this threat by ensuring
@@ -199,9 +192,6 @@
199192
<description>A malicious agent could use an unauthorized peripheral device such as a microphone, connected to
200193
the TOE audio out peripheral device interface to eavesdrop or transfer data across an air‐gap through
201194
audio signaling.</description>
202-
203-
<addressed-by>FDP_APC_EXT.1 (Modified)</addressed-by><rationale>Mitigates this threat by
204-
preventing data and electrical signals from flowing between connections.</rationale>
205195
<addressed-by>FDP_AFL_EXT.1</addressed-by><rationale>Mitigates this threat by ensuring
206196
outgoing signals are filtered to within the range of human hearing.</rationale>
207197
<addressed-by>FDP_PDC_EXT.2/AO</addressed-by><rationale>Mitigates this threat by only
@@ -214,22 +204,14 @@
214204

215205
<threat name="T.SIGNAL_LEAK">
216206
<from base="bpp-psd"/>
217-
<addressed-by>FDP_APC_EXT.1 (Modified)</addressed-by><rationale>Mitigates this threat by
218-
requiring restrictions on how signals are routed between interfaces.</rationale>
219-
<addressed-by>FDP_PDC_EXT.1 (Modified)</addressed-by><rationale>Mitigates this threat by
220-
requiring connections to be only from an authorized list of peripheral devices.</rationale>
221207
<addressed-by>FDP_AFL_EXT.1</addressed-by><rationale>Mitigates this threat by ensuring
222208
signals are filtered within the range of human hearing.</rationale>
223209
<addressed-by>FDP_UDF_EXT.1/AO</addressed-by><rationale>Mitigates this threat by ensuring
224210
signals transit unidirectionally between interfaces.</rationale>
225211
</threat>
226212

227213
<threat name="T.UNAUTHORIZED_DEVICES">
228-
<from base="bpp-psd"/>
229-
<addressed-by>FDP_APC_EXT.1 (Modified)</addressed-by><rationale>Mitigates this threat by
230-
requiring restrictions on how signals are routed between interfaces.</rationale>
231-
<addressed-by>FDP_PDC_EXT.1 (Modified)</addressed-by><rationale>Mitigates this threat by
232-
requiring connections to be only from an authorized list of peripheral devices.</rationale>
214+
<from base="bpp-psd"/>
233215
<addressed-by>FDP_PUD_EXT.1</addressed-by><rationale>Mitigates this threat by not
234216
allowing power to be connected to any unauthorized device.</rationale>
235217
</threat>

0 commit comments

Comments
 (0)