|
|
I-0420: Attribute Inheritance/Modification Rules Need To Be Included In Policy |
TYPE: NIAP Interpretation
NUMBER: I-0420
STATUS: Approved by CCEVS Management and Mailed to Public Mailing
List
TITLE: Attribute Inheritance/Modification Rules Need To Be
Included In Policy
SUPERSEDES:
I-0363 Attribute Inheritance/Modification Rules Need To Be Included In Policy
APPROVAL POSTING: [cc-cmt 00143]
EFFECTIVE: 2002-08-22
SOURCE REFERENCE: CC v2.1 Part 2 Annex F FDP
CC v2.1 Part 2 Clause 6 FDP
RELATED TO:
I-0363 Attribute Inheritance/Modification Rules Need To Be Included In Policy
CCIMB ENTRY: CCIMB-INTERP-0107
ISSUE:The Common Criteria does not currently provide functional requirements for specifying policies related to security attribute modification.STATEMENTRules relating to modification and inheritance of security attributes are part of a Security Function Policy.RECOMMENDED CRITERIA CHANGESTo address this interpretation, the following changes are made to CC v2.1,
Part 2 (additions marked
thusly; deletions marked
SUPPORT:FMT_MSA.1.1 only allows the specification of the roles permitted to make selected security attribute modifications. However, the FMT_MSA component provides no ability to specify policies related to security attribute modification, such as how new objects inherit security attributes from creating subjects, or ancillary rules that control security attribute modification. For example, one cannot use FMT_MSA to specify a rule that a Mandatory Access Control SFP must be satisfied in order to set security attributes controlled under a Discretionary Access Control policy.One might think that such rules could be specified under FDP_ACF or FDP_ICF. However, those families allow specification of rules related to access of objects, not how security attributes obtain values. Providing a place to specify such rules appears to be an omission in the CC. This interpretation corrects that omission. |