| Type: Editorial/Grammatical Change | Source: US NI 347 | Date: 01/13/2003 |
| Status: Closed | Source #: US NI 347 | |
| CC Part #1 Reference: | ||
| CC Part #2 Reference: CC Part 2, FIA_UID | ||
| CC Part #3 Reference: | ||
| CEM Reference: | ||
| Reason: National Interpretation | ||
| Problem: In the FIA_UID family, the CC specifically calls for the inclusion of the user identity in the audit record, even though it is possible that a user, confused by the I&A protocol, provides a password when the user identity is requested. There may be other instances in the CC where the audit requirement either explicitly or implicitly requires data to be logged that might be sensitive. Yet, the example given in CC Part 2, Annex C, paragraph 558, under FAU_GEN, suggests that the CC's intention was to allow the PP/ST author to exclude sensitive data from the required data to be logged. However, this paragraph is in a non-normative portion of the CC. Please clarify. |
||
| Proposed Solution:
The CC should allow PP/ST authors to selectively exempt specific sensitive attribute data from being placed into audit records while still being able to claim compliance with one of the three levels of selecting security-relevant audit events (minimum, basic, detailed).
To address this interpretation, the following changes are made to CC v2.1, Part 2: (additions marked thusly; deletions marked
RATIONALE This interpretation modifies the CC as changed by I-0410. In the FCS_CKM family, the audit events specifically exclude secret or private keys from the attributes to be logged; in some other cases, such as FPT_ITI and FIA_SOS, no attributes are to be logged, presumably because they may contain secrets. This leads one to believe that the CC's goal is not to record sensitive information in the audit trail. However, in the FIA_UID family, the CC specifically calls for the inclusion of the user identity in the audit record, even though it is possible that a user, confused by the I&A protocol, provides a password when the user identity is requested. The example given in CC Part 2, Annex C, paragraph 558, under FAU_GEN, suggests that the CC's intention was to allow the PP/ST author to exclude sensitive data from the required data to be logged. However, this paragraph is in a non-normative portion of the CC. This interpretation permits an author to exclude information, when justification is provided. Such a justification would be provided as part of the explanation of the assignment operation called out in FAU_GEN.1.1b. |
||