ZXR10M6000&T8000&8900ESecurityTarget
5.1.2.13FIA_UAU.2Userauthenticationbeforeanyaction
FIA_UAU.2.1TheTSFshallrequireeachadministratortobesuccessfullyauthenticated
beforeallowinganyotherTSF-mediatedactionsonbehalfofthatadministrator.
5.1.2.14FIA_UAU.5Multipleauthenticationmechanisms
FIA_UAU.5.1TheTSFshallprovide[clientRADIUS,TACACS+,andlocalauthentication
mechanisms]tosupportuserauthentication.
FIA_UAU.5.2TheTSFshallauthenticateanyuser'sclaimedidentityaccordingtothe
[authenticationmechanismspeciedbytheauthoriseduser].
5.1.2.15FIA_UID.2Useridentificationbeforeanyaction
FIA_UID.2.1TheTSFshallrequireeachusertobesuccessfullyidentiedbeforeallowing
anyotherTSF-mediatedactionsonbehalfofthatuser.
5.1.2.16FMT_MOF.1Managementofsecurityfunctionsbehaviour
FMT_MOF.1.1TheTSFshallrestricttheabilityto[determinethebehaviourof]the
functions[TOEmanagement/administration/securityfunctionslistedbelowlistedbelow]
to[theAdministrator].
1.ConguringAdministrators;
2.ConguringLogincontrol;
3.Conguringlocal/RADIUS/TACACS+authentication;
4.ConguringPasswordManagementParameters;
5.ConguringACL;
6.ConguringEventlogs;
7.ConguringSNMP/SYSLOG;
8.ConguringNTP;
9.Conguringanti-DoSattack;
10.ConguringURPF;
11.ConguringCPUProtectionPolicies;
5.1.2.17FMT_MSA.1Managementofsecurityattributes
FMT_MSA.1.1TheTSFshallenforcethe[unauthenticatedSFPandEXPORTSFP]to
restricttheabilityto[changedefault,query,modify,delete]thesecurityattributes[dened
inFDP_IFF.1.1(1)andFDP_IFF.1.1(2)]to[Administrator].
5.1.2.18FMT_MSA.3Staticattributeinitialization
FMT_MSA.3.1TheTSFshallenforcethe[unauthenticatedSFPandEXPORTSFP]to
provide[restrictive]defaultvaluesforsecurityattributesthatareusedtoenforcetheSFP .
5-8
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION