Cisco Cat4K NDPP ST 11 March 2014
EDCS-1228241
49
Ability to update the TOE, and to verify the updates using the
digital signature capability (FCS_COP.1(2)) and [no other
functions]
Ability to manage the cryptographic functionality
Ability to manage the audit logs and functions
Ability to manage routing tables
Ability to manage security attributes belonging to
individual users
Ability to manage the default values of the security
attributes
Ability to manage the warning banner message and
content
Ability to manage the time limits of session inactivity.
5.2.5.3 FMT_SMR.1: Security roles
FMT_SMR.1.1 The TSF shall maintain the roles:
[Security Administrator,
[ No other roles]].
FMT_SMR.1.2 The TSF shall be able to associate users with roles.
5.2.6 Protection of the TSF (FPT)
5.2.6.1 FPT_ITT.1(1) Basic Internal TSF Data Transfer Protection (Disclosure)
FPT_ITT.1.1(1) Refinement: The TSF shall protect TSF data from disclosure when
it is transmitted between separate parts of the TOE through the
use of the TSF-provided cryptographic services:
[FCS_IPSEC_EXT.1 IPSEC].
5.2.6.2 FPT_ITT.1(2) Basic Internal TSF Data Transfer Protection (Modification)
FPT_ITT.1.1(2) Refinement: The TSF shall detect modification of TSF data when
it is transmitted between separate parts of the TOE through the
use of the TSF-provided cryptographic services:
[FCS_IPSEC_EXT.1 IPSEC].
5.2.6.3 FPT_PTD_EXT.1(1): Management of TSF data (for reading of
authentication data)
FPT_PTD_EXT.1.1(1) The TSF shall prevent reading of the plaintext passwords.