ND-iTC / Documents

ND iTC Document repository (NDcPP, ND SD, and all related files)
MIT License
5 stars 1 forks source link

[cPP ENHANCEMENT] Configurable audit recrods. #293

Open OlegAndrianov opened 1 year ago

OlegAndrianov commented 1 year ago

Provide the location of the issue FMT_SMF.1.1 [SD] Paragraph 21

What is the enhancement request for the cPP? Please describe. [SD] Paragraph 21 states that "If the TOE allows configuration of the level of auditing without taking the TOE out of the evaluated configuration, some of the audit events required by FAU_GEN.1 may only be recorded after corresponding configuration of the audit functionality.", but this configuration is not mentioned in FMT_SMF.1.1

Describe the solution you'd like Clarify selection option for FTM_SMF1.1 to include the configuration of audited events. "Ability to configure audit behavior (e.g. changes to the audit events being audited, changes to storage locations for audit; changes to behavior when local audit storage space is full);"

Describe alternatives you've considered Leave that as-is, makes this option for configuration obscure, resulting in vendors trying to meet all FAU_GEN.1 requirements automatically.

Additional context

kr15tyk commented 3 months ago

A similar discussion is currently happening in the NIT. Updates will be provided as they become available.