Commit f9b09eb2 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Updated AAC_AUTH-11 wording

Closes #512
parent 118623bb
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -1317,7 +1317,7 @@ These requirements apply to the product, regardless of the product's use case an
    * material request parameters
    * policy version or rule identifier
    * and validity interval.
* **AAC_AUTH-11** The product shall prevent execution of such privileged action when the authorisation decision is absent, expired, inconsistent with current policy or context, or cannot be recorded as an auditable event except if the action aims to enable or restore auditability of the product.
* **AAC_AUTH-11** The product shall prevent the execution of any privileged action when the authorisation decision is absent, expired, inconsistent with current policy or context, or cannot be recorded as an auditable event, except the action aims to enable or restore auditability of the product.

The requirement **AAC_AUTH-5:** is intentionally vague.
The model can be complex, and there can be multiple different overlapping mechanisms in place that can be used to enable the same function.