commoncriteria / operatingsystem

Protection Profile for Operating Systems
The Unlicense
9 stars 6 forks source link

Offload Audit Records is not really FAU_GEN.1.1.c #114

Open adelton opened 2 years ago

adelton commented 2 years ago

The Configuration Annex's Configuration Requirements table lists Configuration action "Configure the System to Offload Audit Records to a Log Server" with PP reference FAU_GEN.1.1.c. However, that SFR is about Audit Data Generation, while offloading the audit records to remote machine configures what to do with those records once they've been generated. For that reason, I don't believe the PP reference FAU_GEN.1.1.c is correct. The FTP_ITC_EXT.1 seems to be more fitting, since the O.ACCOUNTABILITY section also says

Rationale: FAU_GEN.1 defines the auditable events that must be generated to diagnose the cause of unexpected system behavior. FTP_ITC_EXT.1 provides a mechanism for the TSF to transmit the audit data to a remote system.