Specifications

59
6.2.11 FIA_UAU_(EXT).5(2) Remote authentication mechanisms
FIA_UAU_(EXT).5.1(2) The TOE IT Environment shall provide a remote authentication mechanism to provide
TOE remote user authentication.
FIA_UAU_(EXT).5.2(2) The TOE IT Environment shall authenticate any user’s claimed identity according to the
[AAA authentication policies defined on the Controller].
6.2.12 FIA_UID.1 Timing of identification
FIA_UID.1.1 The TOE IT environment shall allow [no mediated actions] on behalf of the TOE remote
user to be performed before the user is identified.
FIA_UID.1.2 The TOE IT environment shall require each TOE remote user to identify itself before
allowing any other IT environment or TSF-mediated actions on behalf of that TOE remote
user.
6.2.13 FMT_MOF.1(4) Management of Security Functions Behavior
FMT_MOF.1.1(4) The TOE IT environment shall restrict the ability to determine the behavior of disable,
enable, modify the behaviour of the functions: [
• Audit,
• Remote Authentication
• Time service]
to [the administrator].
6.2.14 FMT_MTD.1(4) Management of time data
FMT_MTD.1.1(4) The TOE IT environment shall restrict the ability to [set] the [time and date used to form the
time stamps in FPT_STM.1] to [the Security Administrator or authorized IT entity].
6.2.15 FMT_MTD.1(5) Management of Audit Pre-selection Data
FMT_MTD.1.1(5) The TOE IT environment shall restrict the ability to query, modify, clear, create the set of
rules used to pre-select audit events to [the administrator].
6.2.16 FMT_SMR.1(2) Security roles
FMT_SMR.1.1(2) The TOE IT environment shall maintain the roles [administrator].
FMT_SMR.1.2(2) The TOE IT environment shall be able to associate users with roles.
6.2.17 FTP_ITC_(EXT).1(2) Inter-TSF trusted channel
FTP_ITC_(EXT).1.1(2) The TOE IT environment shall provide an encrypted communication channel between
itself and the TOE that is logically distinct from other communication channels and provides
assured identification of its end points and protection of the channel data from modification or
disclosure.
FTP_ITC_(EXT).1.2(2) The TOE IT Environment shall permit the TSF, or the TOE IT Environment entities to
initiate communication via the trusted channel.