
McAfee Email Gateway
Security Target
Page 42 of 61
Requirement Auditable Events
Additional Audit Record
Contents
FPT_STM.1 Changes to the time.
The old and new values for the
time.
Origin of the attempt (e.g., IP
No additional information.
FPT_TST_EXT.1 None None
FTA_SSL_EXT.1
Any attempts at unlocking of an
interactive session.
No additional information.
FTA_SSL.3
The termination of a remote session
by the session locking mechanism.
No additional information.
FTA_SSL.4
The termination of an interactive
session
No additional information.
FTP_ITC.1
Initiation of the trusted channel.
Termination of the trusted channel.
Failure of the trusted channel
Identification of the initiator and
target of failed trusted channels
establishment attempt.
FTP_TRP.1
Initiation of the trusted channel.
Termination of the trusted channel.
Failures of the trusted path
Identification of the claimed user
identity.
Table 13 - TOE Security Functional Requirements and Auditable Events
5.2.2 Security Audit (FAU)
FAU_GEN.1 Audit Data Generation
FAU_GEN.1.1 The TSF shall be able to generate an audit record of the following auditable events:
a) Start-up of the audit functions;
b) All auditable events for the [not specified] level of audit; and
c) [All administrative actions;
d) Specifically defined auditable events listed in Table 13].
FAU_GEN.1.2 The TSF shall record within each audit record at least the following information:
a) Date and time of the event, type of event, subject identity, and the outcome
(success or failure) of the event; and
b) For each audit event type, based on the auditable event definitions of the
functional components included in the PP/ST, [information specified in
column three of Table 13].
FAU_GEN.2 User Identity Association
FAU_GEN.2.1 For audit events resulting from actions of identified users, the TSF shall be able to
associate each auditable event with the identity of the user that caused the event.
Komentáře k této Příručce