Commit bb96f3af authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Updated evidence collection and added missing objectives to assessments

Closes #525
parent d532c178
Loading
Loading
Loading
Loading
+32 −33
Original line number Diff line number Diff line
@@ -2396,7 +2396,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2421,7 +2421,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2445,7 +2445,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2470,7 +2470,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2495,7 +2495,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2521,7 +2521,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2529,8 +2529,7 @@ Verify that:

### 6.6.7 AAC_AUTH-7

**Objective:**   
**Preparation:**
**Objective:** Ensure confidentiality of the IAM.  

1. Have the product initialised and available with the default configuration and required credentials;
2. Study the technical documentation how to interact with the system;
@@ -2547,7 +2546,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2555,7 +2554,7 @@ Verify that:

### 6.6.8 AAC_AUTH-8

**Objective:**   
**Objective:** Ensure auditability of the system.  
**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2572,7 +2571,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2580,7 +2579,7 @@ Verify that:

### 6.6.10 AAC_AUTH-9

**Objective:**   
**Objective:** Ensure privileged action correctens a the time of the execution.  
**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2597,7 +2596,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2605,7 +2604,7 @@ Verify that:

### 6.6.11 AAC_AUTH-10

**Objective:**   
**Objective:** Ensure auditability of the system.  
**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2623,7 +2622,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2631,7 +2630,7 @@ Verify that:

### 6.6.12 AAC_AUTH-11

**Objective:**   
**Objective:** Ensure auditability of the system.  
**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2649,7 +2648,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2657,7 +2656,7 @@ Verify that:

### 6.6.1.1 AAC_MACHINE-1

**Objective:**   
**Objective:** Make pre-shared keys and fixed passwords obsolete.  
**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2674,7 +2673,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -2682,7 +2681,7 @@ Verify that:

### 6.6.1.2 AAC_MACHINE-2

**Objective:**   
**Objective:** Prevent general super user access rights for M2M traffic IAM.  
**Preparation:**

1. Have the product initialised and available with the default configuration and required credentials;
@@ -2699,7 +2698,7 @@ Verify that:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3517,7 +3516,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3543,7 +3542,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3569,7 +3568,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3594,7 +3593,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3621,7 +3620,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3648,7 +3647,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3675,7 +3674,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3701,7 +3700,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3727,7 +3726,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3754,7 +3753,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3794,7 +3793,7 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
@@ -3947,7 +3946,7 @@ Outcomes:

**Supporting Evidence:**

* Metrics output showing detected system or managed element crash or restart with the reported cause;
* Metrics output relevant for the activities, if available;
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;