Commit e0534430 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Review updates for DM_ topic

Closes #573, #574, #575, #576
parent ed5dc94a
Loading
Loading
Loading
Loading
+8 −7
Original line number Diff line number Diff line
@@ -3096,11 +3096,12 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
**Activities:**

1. Cross-reference the product settings and output to the documentation.
2. List the event types the product collects from managed elements out of present log files.

**Verdict:**

1. Pass the presented categories matches the product operation
2. and the listed retention times of the log records are fit for the expected use of the product.
2. and the listed retention times of the log records match with the expected use of the product.
3. Fail otherwise.

**Supporting Evidence:**
@@ -3110,9 +3111,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
* Logs, configuration files, or audit traces demonstrating the implementation of the requirement;

### 6.9.1 DM_RETENTION-2
### 6.9.2 DM_RETENTION-2

**Objective:** Ensure that the product user understands what data is being collected.
**Objective:** The product collects only those metric data that are documented to the product user.

**Preparation:**

@@ -3125,8 +3126,8 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re

**Verdict:**

1. Pass the listed information is available in the technical documentation
2. and the collected metrics and the implemented storage matches the documentation.
1. Pass, if the listed metric data types are available in the technical documentation
2. and the collected metrics and the stored metric records matches the documentation.
3. Fail otherwise.

**Supporting Evidence:**
@@ -3136,9 +3137,9 @@ Assessments are defined in [Annex K](#annex-k-normative-generic-cryptographic-re
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
* Logs, configuration files, or audit traces demonstrating the implementation of the requirement;

### 6.9.1 DM_RETENTION-3
### 6.9.3 DM_RETENTION-3

**Objective:** Ensure that the product user understands what data is being collected.
**Objective:** The product collects only those metric data types that are defined in the technical documentation.

**Preparation:**