8(495)909-90-01
8(964)644-46-00
pro@sio.su
Главная
Системы видеонаблюдения
Охранная сигнализация
Пожарная сигнализация
Система пожаротушения
Система контроля удаленного доступа
Оповещение и эвакуация
Контроль периметра
Система домофонии
Парковочные системы
Проектирование слаботочных сетей
Аварийный
контроль
Раздел: Документация

0 ... 29 30 31 32 33 34 35 ... 73

ado del.2.1c The delivery documentation shall describe all procedures that are necessary to maintain security when distributing versions of the TOE to a users site.

ado del.2.2c The delivery documentation shall describe how the various procedures and technical measures provide for the detection of modifications, or any discrepancy between the developers master copy and the version received at the user site.

ado del.2.3c The delivery documentation shall describe how the various procedures allow detection of attempts to masquerade as the developer, even in cases in which the developer has sent nothing to the users site.

Evaluator action elements:

ado del.2.ie The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence.

ADO DEL.3 Prevention of modification

Dependencies:

ACMCAP.3 Authorisation controls

Developer action elements:

ado del.3.id The developer shall document procedures for delivery of the TOE or parts of it to the user.

ado del.3.2d The developer shall use the delivery procedures. Content and presentation of evidence elements:

ado del.3.ic The delivery documentation shall describe all procedures that are necessary to maintain security when distributing versions of the TOE to a users site.

ado del.3.2c The delivery documentation shall describe how the various procedures and technical measures provide for the prevention of modifications, or any discrepancy between the developers master copy and the version received at the user site.

ado del.3.3c The delivery documentation shall describe how the various procedures allow detection of attempts to masquerade as the developer, even in cases in which the developer has sent nothing to the users site.

Evaluator action elements:


9.2 Installation, generation and start-up (ADO IGS) Objectives

Installation, generation, and start-up procedures are useful for ensuring that the TOE has been installed, generated, and started up in a secure manner as intended by the developer. The requirements for installation, generation and start-up call for a secure transition from the TOEs implementation representation being under configuration control to its initial operation in the user environment.

Component levelling

The components in this family are levelled on the basis of whether the TOE generation options are

logged.

Application notes

It is recognised that the application of these requirements will vary depending on aspects such as whether the TOE is an IT product or system, whether it is delivered in an operational state, or whether it has to be brought up at the TOE owners site, etc. For a given TOE, there will normally be a division of responsibility with respect to installation, generation and start-up between the TOE developer and the owner of the TOE, but there are examples where all activities take place at one site. For example, for a smart card all aspects of installation, generation and start-up may have been performed at the TOE developers site. On the other hand the TOE might be delivered as an IT system in the form of software, where all aspects of installation, generation and start-up are carried out at the TOE owners site.

It might also be the case that the TOE is already installed by the time the evaluation starts. In this case it may be inappropriate to demand and analyse installation procedures.

Furthermore, the generation requirements are applicable only to TOEs that provide the ability to generate portions of an operational TOE from its implementation representation.

The installation, generation, and start-up procedures may exist as a separate documents or could be grouped with other administrative guidance. The requirements in this assurance family are presented separately from those in the AGD ADM family, due to the infrequent, possibly one-time use of the installation, generation and start-up procedures.

ADO IGS.1 Installation, generation, and start-up procedures

Dependencies:

AGDADM.1 Administrator guidance

Developer action elements:

ado igs.i.id The developer shall document procedures necessary for the secure installation, generation, and start-up of the TOE.


ado igs.i.ic The documentation shall describe the steps necessary for secure installation, generation, and start-up of the TOE.

Evaluator action elements:

ado igs.i.ie The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence.

ado igs.i.2e The evaluator shall determine that the installation, generation, and start-up procedures result in a secure configuration.

ADO IGS.2 Generation log

Dependencies:

AGDADM. 1 Administrator guidance

Developer action elements:

ado igs.2.id The developer shall document procedures necessary for the secure installation, generation, and start-up of the TOE.

Content and presentation of evidence elements:

ado igs.2.ic The documentation shall describe the steps necessary for secure installation, generation, and start-up of the TOE.

ado igs.2.2c The documentation shall describe procedures capable of creating a log containing the generation options used to generate the TOE in such a way that it is possible to determine exactly how and when the TOE was generated.

Evaluator action elements:

ado igs.2.ie The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence.

ado igs.2.2e The evaluator shall determine that the installation, generation, and start-up procedures result in a secure configuration.



0 ... 29 30 31 32 33 34 35 ... 73