Installation guide

Motorola WS5100 Wireless Switch and RFS7000 RF Switch Security Target
Page 37 of 85
5.3.1.17 FMT_MTD.1(5) Management of time data
FMT_MTD.1.1(5) The TOE IT environment shall restrict the ability to [set] the [time and date used
to form the time stamps in FPT_STM.1] to [the Security Administrator or authorized IT entity].
5.3.1.18 FMT_SMR.1(2) Security roles
FMT_SMR.1.1(2) The TOE IT environment TSF shall maintain the roles [administrator].
FMT_SMR.1.2(2) The TOE IT environment TSF shall be able to associate users with roles.
Application Note: The TOE IT environment must include an administrative role for its own management.
5.3.1.19 FTP_ITC_EXP.1(2) Inter-TSF trusted channel
FTP_ITC_EXP.1.1(2) The TOE IT environment TSF shall provide an IPSec/IKE encrypted
communication channel between itself and the TOE that is logically distinct from other
communication channels and provides assured identification of its end points and protection of the
channel data from modification or disclosure.
FTP_ITC_EXP.1.2(2) The TOE IT Environment TSF shall permit the TSF, or the TOE IT
Environment entities to initiate communication via the trusted channel.
FTP_ITC_EXP.1.3(2) The TOE IT environment TSF shall initiate communication via the trusted
channel for [all authentication functions, remote logging, time, none].
Application Note: For FTP_ITC_EXP.1.1(2) it is expected that the environment be able to provide and
encrypted channel between the environment and the TOE. This is to provide for communications between
itself and the TOE, as end points, to protect the communications between the TOE and the IT environment.
5.3.1.20 FPT_RVM.1(2) Non-bypassability of the IT Environment Security Policy (TSP)
FPT_RVM.1.1(2) The TOE IT Environment TSF shall ensure that IT environment TSP
enforcement functions are invoked and succeed before each function within the IT environmental
scope of control TSC is allowed to proceed.
5.3.1.21 FPT_SEP.1(2) TSF domain separation
FPT_SEP.1.1(2) The TOE IT Environment TSF shall maintain a security domain for its own
execution that protects it from interference and tampering by untrusted subjects.
FPT_SEP.1.2(2) The TOE IT Environment TSF shall enforce separation between the security
domains of subjects in the IT environmental scope of control.
5.3.1.22 FPT_STM.1 Reliable time stamps
FPT_STM.1.1 The TOE IT environment TSF shall be able to provide reliable time and date
stamps for the TOE and its own use.