Commit f5c9ea38 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Update file EN-304-624.md

parent d611a1d1
Loading
Loading
Loading
Loading
+6 −23
Original line number Diff line number Diff line
@@ -2781,7 +2781,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
  - Test execution records mapping each test activity to its corresponding audit event.
  - List of executed test cases and their corresponding timestamps and log entries.

- REFERENCE: ACC_PKI_MON_02
- REFERENCE: ACC-PKI-MON-02
  - OBJECTIVE:
    - Verify that the product records within each audit record the required information, and that these records do not include any secret key or other secret parameter in plaintext form.
  - PREPARATION:
@@ -2800,7 +2800,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
    - FAIL: Audit records are missing required fields, contain incorrect values, or expose secret/sensitive key material in plaintext.
  - EVIDENCE: The way the events were triggered and at what time, and the corresponding audit records.

- REFERENCE: ACC_PKI_MON_03
- REFERENCE: ACC-PKI-MON-03
  - OBJECTIVE:
    - Verify that the product employs reliable time stamps.
  - PREPARATION:
@@ -2818,7 +2818,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
    - arguments relating to the authentication of a trusted source (if applicable);
    - arguments relating to the monotonicity of local time information (if applicable).

- REFERENCE: ACC_PKI_MON_04
- REFERENCE: ACC-PKI-MON-04
  - OBJECTIVE:
    - Verify that the product records within each audit record resulting from actions of identified users the corresponding user information.
  - PREPARATION:
@@ -2834,24 +2834,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
    - The identity of the given user used for the test;
    - the way the event was triggered and at what time, and the corresponding audit record.

- REFERENCE: ACC_PKI_MON_05
  - OBJECTIVE:
    - Verify product protections from unauthorised deletion to be active and functional.
  - PREPARATION: 
    - Ability to identify to the product as a given user, unauthorised to perform audit record deletion. Ability to trigger auditable events as a user, and ability to audit events.
    - Listof all actions that may result in deletion of an audit record. Depending on this list of actions, several distinct users with distinct authorizations may be used.
  - ACTIVITIES:
    - Login as the given user. Trigger an auditable event as the given user. Access and copy audit records separately.
    - Attempt to perform all actions identified as possibly resulting in an audit record deletion; re-identifying to the product as necessary.
    - Access audit records and verify they match the copy performed previously.
  - VERDICT: SUCCESS if the verification passes; else FAIL.
  - EVIDENCE:
    - The identity of the given user(s) used for the test;
    - the list of identified actions that may result in deletion of an audit records;
    - the way the actions were attempted, including the corresponding user identity;
    - the copies of existing audit records, before and after attempts.

- REFERENCE: ACC_PKI_MON_06
- REFERENCE: ACC-PKI-MON-05
  - OBJECTIVE:
    - Verify the product's prevention of auditable events, except those taken by the auditor, if the audit log is full.
  - PREPARATION: 
@@ -2868,7 +2851,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
    - the size of the audit when full, or nearly so;
    - the way the additional event was attempted to be triggered, and the corresponding response from the product.

- REFERENCE: ACC_PKI_MON_07
- REFERENCE: ACC-PKI-MON-07
  - OBJECTIVE:
    - Verify the use of an audit log signing event by the product.
  - PREPARATION: Ability to trigger auditable events, and ability to audit events.
@@ -2898,7 +2881,7 @@ As stated in clause 5.10, since minimizing the impact on other systems relies on
    - the way the audit record of the triggered event was modified;
    - the way the second-to-last signature, keyed hash or authentication code was modified.

- REFERENCE: ACC_PKI_MON_08
- REFERENCE: ACC-PKI-MON-08
  - OBJECTIVE:
    - Verify the frequency of the audit log signing event by the product to be configurable.
  - PREPARATION: