ZXR10M6000&T8000&8900ESecurityTarget
OBJECTIVESSFRRationale
lFPT_STM.1ensuresthatreliabletime
stampsareprovidedforauditrecords
lFTP_ITC.1(3)requiresthatthetimestampis
protectedbytrustedchannels.
O.MANAGE
TheTOEmustprovideservicesthatallow
effectivemanagementofitsfunctionsanddata
andrestrictaccesstotheTOEManagement
functionstotheprivilegedadministratorsand
authenticationadministrators.
Thisobjectiveismetby:
lFMT_MOF.1allowstheauthorizedusers
(roles)tomanagethebehavioroffunctions
intheTSFthatuserulesorhavespecied
conditionsthatmaybemanageable.
lFMT_MSA.1andFMT_MSA.3assistin
effectivesecurityattributemanagement.
lFMT_MTD.1restrictstheadministrator’s
abilitytomodifytheTSFdata.
lFMT_SMF.1liststhesecuritymanagement
functionsthatmustbecontrolled.
lFMT_SMR.1denestherolesonwhich
accessdecisionsarebased.
lFTP_ITC.1(1)requiresthatatrustedchannel
betweentheTSFandtheremoteclientbe
providedforremoteadministration.
O.IDAUTH
TheTOEmustuniquelyidentifyandauthenticate
theclaimedidentityofalladministrativeusers
beforegrantingmanagementaccess.
Thisobjectiveismetby:
lFIA_AFL.1requiresthattheTSFbeableto
terminatethesessionestablishmentprocess
afteraspeciednumberofunsuccessful
userauthenticationattempts.Italso
requiresthat,afterterminationofthesession
establishmentprocess,theTSFbeableto
disabletheuseraccountorthepointofentry
(e.g.workstation)fromwhichtheattempts
weremadeuntilanadministrator-dened
conditionoccurs.
lFIA_SOS.1speciesmetricsfor
authenticationtorestrictaccess.
lFIA_UAU.2ensuresthatusersare
authenticatedtotheTOEtorestrictaccess.
lFIA_UAU.5wasselectedtoensurethat
appropriateauthenticationmechanismscan
beselectedtorestrictaccess.
lFIA_UID.2ensuresthatusersareidentied
totheTOEtorestrictaccess.
7-4
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION