|
|
I-0410: Auditing Of Subject Identity For Unsuccessful Logins |
TYPE: NIAP Interpretation
NUMBER: I-0410
STATUS: Approved by CCEVS Management and Mailed to Public Mailing
List
TITLE: Auditing Of Subject Identity For Unsuccessful Logins
APPROVAL POSTING: [cc-cmt 00094]
EFFECTIVE: 2002-01-04
SOURCE REFERENCE: CC v2.1 Part 2 Subclause 3.2 FAU_GEN.1
CC v2.1 Part 2 Subclause 3.2 FAU_GEN.2
CC v2.1 Part 2 Subclause C.2 FAU_GEN.1
CC v2.1 Part 2 Subclause C.2 FAU_GEN.2
RELATED TO: <None>
CCIMB ENTRY: CCIMB-INTERP-0203
ISSUE:Both the FIA_UAU and FIA_UID components call for auditing of unsuccessful logins. However, if the login is unsuccessful, there is no subject identity to put in the audit record (as there is no subject in place). This is an inconsistency.In a similar fashion, FAU_GEN.2.1 cannot be satisfied in the face of an invalid login, for there is no identity of the user that caused the event. STATEMENTFor unsuccessful login attempts, it is acceptable to not include the subject identity in the login record.RECOMMENDED CRITERIA CHANGESTo address this interpretation, the following changes are made to CC v2.1 Part
2: (additions marked
thusly; deletions marked
SUPPORT:At the time of an unsuccessful login, there is no user subject whose identity can be recorded. Similarily, there is no validated user identity to associate with that audit event. Thus, it is appropriate to not include such information in the audit record, or to record an indication that the indicated field is not applicable. |