Cisco Cat4K NDPP ST
11 March 2014
EDCS-1228241
49
Ability to update the TOE, and to verify the updates using the
digital signature capability (FCS_COP.1(2)) and
[
no other
functions
]
Ability to manage the cryptographic functionality
Ability to manage the audit logs and functions
Ability to manage routing tables
Ability to manage security attributes belonging to
individual users
Ability to manage the default values of the security
attributes
Ability to manage the warning banner message and
content
Ability to manage the time limits of session inactivity
.
5.2.5.3
FMT_SMR.1: Security roles
FMT_SMR.1.1 The TSF shall maintain the roles:
[Security Administrator,
[
No other roles
]].
FMT_SMR.1.2 The TSF shall be able to associate users with roles.
5.2.6 Protection of the TSF (FPT)
5.2.6.1
FPT_ITT.1(1) Basic Internal TSF Data Transfer Protection (Disclosure)
FPT_ITT.1.1(1)
Refinement:
The TSF shall protect TSF data from disclosure when
it is transmitted between separate parts of the TOE
through the
use
of
the
TSF-provided
cryptographic
services:
[
FCS_IPSEC_EXT.1 IPSEC
].
5.2.6.2
FPT_ITT.1(2) Basic Internal TSF Data Transfer Protection (Modification)
FPT_ITT.1.1(2)
Refinement:
The TSF shall detect modification of TSF data when
it is transmitted between separate parts of the TOE
through the
use
of
the
TSF-provided
cryptographic
services:
[
FCS_IPSEC_EXT.1 IPSEC
].
5.2.6.3
FPT_PTD_EXT.1(1): Management of TSF data (for reading of
authentication data)
FPT_PTD_EXT.1.1(1) The TSF shall
prevent
reading of
the
plaintext passwords
.