Chapter5SECURITYREQUIREMENTS
5.1.2SecurityFunctionalRequirements
5.1.2.1FAU_GEN.1Auditdatageneration
FAU_GEN.1.1TheTSFshallbeabletogenerateanauditrecordofthefollowingauditable
events:
1.Start-upandshutdownoftheauditfunctions;
2.(renedaway)
lAlarmlog:Thesecurityeventsourceisalleventsthataffectattemptstobreach
system:
àauthenticationalarm
a.I&Aauthenticationsuccess
b.I&Aauthenticationfailure
àusermanagementalarm
a.useraccountislocked
b.useraccountisunlocked
c.useraccountisenabled
d.useraccountisdisabled
àRADIUSalarmlog
a.RADIUSauthenticationgroupisunreachable
b.RADIUSaccountingservergroupisunreachable
c.RADIUSbufferqueueexceedsthethreshold
àNTPalarmlog
a.TheclockofNTPserverandclientarenotsynchronized
àACLalarm
a.ACLaggregationistoolarge
àRIP/OSPF/IS-IS/BGPalarm
a.authenticationsuccess
b.authenticationfailure
lCommandlog:allactivitiesperformedbytheadministratorarerecordedin
Commandlog.
FAU_GEN.1.2TheTSFshallrecordwithineachauditrecordatleastthefollowing
information:
1.Dateandtimeoftheevent,typeofevent,subjectidentity(ifapplicable),andthe
outcome(successorfailure)oftheevent;and
2.Foreachauditeventtype,basedontheauditableeventdenitionsofthefunctional
componentsincludedintheST[none].
5-3
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION