System information

Cisco Cat3K ST 6 June 2012
28
Requirement Auditable Events Additional Audit Record
Contents
FDP_IFC.1(1),(2),(3) None
FDP_IFF.1(1) None
FDP_IFF.1(2) All decisions on requests for
information flow
None.
FDP_IFF.1(3) IP packet flows denied by
VACL
None
FIA_UAU.2 All use of the authentication
mechanism.
Provided user identity,
origin of the attempt (e.g.,
IP address).
FIA_UAU.5 All use of the authentication
mechanism.
Origin of the attempt (e.g.,
IP address).
FIA_UID.2 All use of the identification
mechanism.
Provided user identity,
origin of the attempt (e.g.,
IP address).
FMT_MOF.1 All modifications in the
behaviour of the functions in
the TSF
None
FMT_MSA.3(1)(2) Modifications of the default
setting of permissive or
restrictive rules and all
modifications of the initial
values of security attributes.
None
FPT_RPL.1 Detected replay attacks. Origin of the attempt (e.g.,
IP address).
FPT_STM.1 Changes to the time. The old and new values for
the time.
Origin of the attempt (e.g.,
IP address).
FPT_TST_EXT.1 Indication that TSF self-test
was completed.
Any additional information
generated by the tests
beyond “success” or
“failure”.
5.2.1.2 FAU_GEN.2: User identity association
FAU_GEN.2.1 For audit events resulting from actions of identified users, the TSF
shall be able to associate each auditable event with the identity of
the user that caused the event.