
McAfee Email Gateway
Security Target
Page 46 of 61
FIA_UAU.7 Protected Authentication Feedback
FIA_UAU.7.1 The TSF shall provide only [obscured feedback] to the administrative user while the
authentication is in progress at the local console.
5.2.6 Security Management (FMT)
FMT_MTD.1 Management of TSF Data (for general TSF data)
FMT_MTD.1.1 The TSF shall restrict the ability to [manage] the [TSF data] to [the Security
Administrators].
FMT_SMF.1 Specification of Management Functions
FMT_SMF.1.1 The TSF shall be capable of performing the following management functions:
• [Ability to administer the TOE locally and remotely;
• Ability to update the TOE, and to verify the updates using [published hash]
capability prior to installing those updates;
• Ability to configure the cryptographic functionality
].
FMT_SMR.2 Restrictions on security roles
FM
T_SMR.2.1 The TSF shall maintain the roles:
• [Authorized Administrator].
FMT_SMR.2.2 The TSF shall be able to associate users with roles.
FMT_SMR.2.3 The TSF shall ensure that the conditions
• [Authorized Administrator role shall be able to administer the TOE locally;
• Authorized Administrator role shall be able to administer the TOE remotely;]
are satisfied.
5.2.7 Protection of the TSF (FPT)
FPT_ITT.1 Basic Internal TSF Data Transfer Protection
FPT_ITT.1.1 The TSF shall protect TSF data from [disclosure
] and detect its modification when it
is transmitted between separate parts of the TOE through the use [TLS
].
FPT_SKP_EXT.1 Extended: Protection of TSF Data (for reading of all symmetric keys)
FPT_SKP_EXT.1.1 The TSF shall prevent reading of all pre-shared keys, symmetric keys, and private
keys.
FPT_APW_EXT.1.1 Extended: Protection of administrator passwords
FPT_APW_EXT.1.1 The TSF shall store passwords in non-plaintext form.
FPT_APW_EXT.1.2 The TSF shall prevent the reading of plaintext passwords.
Commenti su questo manuale