FitCEM Wallet Instance
56 requirements mapped to controls.
Requirements
| Requirement | Title | Controls | Owner |
|---|---|---|---|
| FIT-AR-01 | Unsupported OS version prohibition | SID-HARD-06 | platform |
| FIT-AR-02 | Outdated OS update prompt | SID-HARD-06 | platform |
| FIT-DS-01 | Utilize platform security and privacy functions | SID-CRYPTO-03, SID-CRYPTO-02 | platform |
| FIT-DS-02 | Sensitive data only within wallet instance | SID-CRYPTO-03, SID-DATA-08 | platform |
| FIT-DS-03 | Logs and sensitive data | SID-AUDIT-01, SID-AUDIT-02 | platform |
| FIT-DS-04 | Sensitive data and third parties | SID-PRIV-01, SID-DATA-08 | platform |
| FIT-DS-05 | Disable keyboard cache | SID-HARD-08 | platform |
| FIT-DS-06 | Shoulder surfing / remote surveillance protection | SID-HARD-08 | platform |
| FIT-DS-07 | Deactivate clipboard | SID-HARD-08 | platform |
| FIT-DS-08 | Restricting IPC | SID-HARD-03, SID-HARD-02 | platform |
| FIT-DS-09 | File access permissions | SID-ACCESS-01, SID-ACCESS-02 | platform |
| FIT-DS-10 | Authentication data stored properly | SID-AUTH-01, SID-CRYPTO-02 | platform |
| FIT-DS-11 | Removing data when in background | SID-HARD-08 | platform |
| FIT-DS-12 | Memory and sensitive data | SID-DATA-09 | platform |
| FIT-DS-13 | Encrypting sensitive data | SID-CRYPTO-03, SID-CRYPTO-02, SID-AUTH-05 | platform |
| FIT-DS-14 | Encrypting backups | SID-DATA-10 | platform |
| FIT-DS-15 | No sensitive data in backups | SID-DATA-10 | platform |
| FIT-CR-01 | Basic cryptography requirements | SID-CRYPTO-01, SID-CRYPTO-03, SID-CRYPTO-04, SID-CRYPTO-05 | platform |
| FIT-CR-02 | WI-WSCA communication security | SID-KEY-03, SID-KEY-04 | platform |
| FIT-AU-01 | Wallet Unit Attestation | SID-HARD-06 | platform |
| FIT-AU-02 | Wallet Instance Attestation | SID-HARD-06 | platform |
| FIT-AU-03 | Binding (device and user) | SID-AUTH-01, SID-KEY-03 | platform |
| FIT-AU-04 | Wallet Unlock | SID-AUTH-05 | platform |
| FIT-AU-05 | Deactivation after failed attempts | SID-AUTH-05 | platform |
| FIT-AU-06 | Local retry counter | SID-AUTH-05, SID-KEY-04 | platform |
| FIT-AU-07 | Cryptographic keys for launching wallet | SID-KEY-03, SID-CRYPTO-02 | platform |
| FIT-AU-08 | WSCA communication keys | SID-KEY-03, SID-KEY-04 | platform |
| FIT-AU-09 | Operations on critical assets | SID-KEY-03, SID-KEY-04, SID-AUTH-05 | platform |
| FIT-AU-10 | PIN codes | SID-AUTH-05 | platform |
| FIT-AU-11 | Receiving/storing identification data and attestations | SID-CRYPTO-03, SID-TRANS-02 | platform |
| FIT-AU-12 | Pseudonymous authentication | SID-PRIV-04 | platform |
| FIT-AU-13 | Confirming the relying party | SID-TRUST-03, SID-TRUST-05 | platform |
| FIT-AU-14 | Constructing a presentation | SID-DATA-01, SID-DATA-02, SID-KEY-03 | platform |
| FIT-AU-15 | Presentation response | SID-KEY-03, SID-TRANS-03 | platform |
| FIT-AU-16 | Embedded disclosure policies | SID-PRIV-01 | platform |
| FIT-AU-17 | Attestation issuance | SID-TRANS-02, SID-TRUST-03 | platform |
| FIT-AU-18 | Authentication initiation | SID-HARD-02 | platform |
| FIT-AU-19 | WI–backend communication | SID-TRANS-01, SID-AUTH-04 | platform |
| FIT-AU-20 | Wallet deactivation (user and provider) | SID-AUTH-06 | platform |
| FIT-DC-01 | General data communication requirements | SID-TRANS-01, SID-TRANS-04 | platform |
| FIT-PI-01 | General platform interaction requirements | SID-HARD-02, SID-HARD-08, SID-HARD-05 | platform |
| FIT-PI-02 | Enforcing device access | SID-HARD-06 | platform |
| FIT-CS-01 | Code security, quality and development environment | SID-OPS-08, SID-HARD-02, SID-OPS-04 | platform |
| FIT-SR-01 | Security controls and resilience | SID-HARD-09, SID-HARD-06 | platform |
| FIT-FR-01 | Environment reporting to wallet provider | SID-HARD-06 | platform |
| FIT-FR-02 | Genuine app verification | SID-HARD-06 | platform |
| FIT-FR-03 | OS-version level enforcement (functional) | SID-HARD-06 | platform |
| FIT-NF-01 | All used components are known | SID-OPS-04, SID-OPS-09 | platform |
| FIT-NF-02 | Architecture documentation | SID-OPS-09 | platform |
| FIT-NF-03 | Sensitive data properly identified | SID-OPS-09 | platform |
| FIT-NF-04 | Functionality properly described and documented | SID-OPS-13 | operator |
| FIT-NF-05 | Threat model documented | SID-OPS-09 | platform |
| FIT-NF-06 | User guidance | SID-OPS-13 | operator |
| FIT-NF-07 | Development and security practices | SID-OPS-08, SID-OPS-09 | platform |
| FIT-NF-08 | Cryptographic key management policy | SID-OPS-13, SID-KEY-01, SID-KEY-02, SID-KEY-03, SID-KEY-04 | operator |
| FIT-NF-09 | Security controls validated | SID-OPS-08, SID-OPS-09 | platform |