Cisco ISR 4000 Family Routers Administrator Guidance
Page
56
of
66
Requirement
Management Action to
Log
Sample Log
FMT_MOF.1: Management
of Security Functions
Behavior
See all other rows in
table.
N/A
FMT_MTD.1: Management
of TSF data (for general TSF
data)
See all other rows in
table.
N/A
FMT_SMF.1: Specification
of management functions
See all other rows in
table.
N/A
FMT_SMR.2: Restrictions
on Security roles
Configuring
administrative users with
specified roles.
Feb 15 2013 13:12:25.055: %PARSER-5-
CFGLOG_LOGGEDCMD: User:cisco
logged command: username admin 15
FPT_RUL_EXT.1: Packet
Filtering
Configuring packet
filtering rules.
Feb 15 2013 13:12:25.055: %PARSER-5-
CFGLOG_LOGGEDCMD: User:cisco
logged command: access-list 199 deny ip
10.100.0.0 0.0.255.255 any log-input
FPT_FLS.1: Fail Secure
None
N/A
FPT_SKP_EXT.1: Protection
of TSF Data (for reading of
all symmetric keys)
None
N/A
FPT_APW_EXT.1:
Protection of Administrator
Passwords
None
N/A
FPT_STM.1: Reliable time
stamps
Changes to NTP settings.
Manual changes to the
system time.
Changes to NTP settings:
Manual changes to the system time:
Feb 5 2013 06:28:00.000: %SYS-6-
CLOCKUPDATE: System clock has
been updated from 11:27:52 UTC Tue
Feb 5 2013 to 06:28:00 UTC Tue Feb 5
2013, configured from console by admin
on console.