@@ -1631,7 +1631,7 @@ The assessment criteria for each security requirements are described in a struct
## 6.5 Authentication and access control
### 6.5.1 AC - General
- REFERENCE: ACC_PKI_AC_01
- REFERENCE: ACC_PKI_AAC_01
- OBJECTIVE:
Verify the product allows to create different user profiles (users with different access rights to functions, configuration, and stored data) for the roles defined by PKI policies, each with distinct credentials.
- PREPARATION:
@@ -1654,7 +1654,7 @@ The assessment criteria for each security requirements are described in a struct
- List of validated functionalities and data access rights for each user profile.
- Screenshots or logs of access attempts and rights verification.
- REFERENCE: ACC_PKI_AC_02
- REFERENCE: ACC_PKI_AAC_02
- OBJECTIVE:
- Verify that the product only allows identified and authenticated authorized users to perform access-controlled actions.
- PREPARATION:
@@ -1672,7 +1672,7 @@ The assessment criteria for each security requirements are described in a struct
- Screenshots or logs of access attempts, rights verification, or rejected actions.
### 6.5.2 AC - Monitoring
- REFERENCE: ACC_PKI_AC_03
- REFERENCE: ACC_PKI_AAC_03
- OBJECTIVE: Verify the product's ability to detect unauthorised modifications to the stored audit records during the audit.