• Managing Audits
  • Windows 10
  • Microsoft Windows Common Criteria Evaluation Microsoft Windows 10




    Download 298.26 Kb.
    bet6/60
    Sana04.01.2022
    Hajmi298.26 Kb.
    #4840
    1   2   3   4   5   6   7   8   9   ...   60

    Management Functions


    The following table maps management functions to roles:




    Management Function

    User Guidance

    Local Administrator Guidance

    IT Administrator Guidance

    1

    Configure password policy




    Windows 10

    Windows 10

    Windows 10 Mobile



    2

    Configure session locking policy




    Windows 10

    Windows 10

    Windows 10 Mobile



    3

    Enable/disable the VPN protection




    Windows 10

    Windows 10

    Windows 10 Mobile



    4

    Enable/disable [GPS, Wi-Fi, mobile broadband radios, Bluetooth]







    Windows 10

    Windows 10 Mobile



    5

    Enable/disable [camera, microphone]




    Windows 10

    Windows 10 Mobile

    Windows 10 (Camera only)



    6

    Specify wireless networks (SSIDs) to which the TSF may connect




    Windows 10

    Windows 10

    Windows 10 Mobile



    7

    Configure security policy for connecting to wireless networks




    Windows 10

    Windows 10

    Windows 10 Mobile



    8

    Transition to the locked state

    Windows 10

    Windows 10 Mobile



    Windows 10




    9

    TSF wipe of protected data




    Windows 10

    Windows 10

    Windows 10 Mobile



    10

    Configure application installation policy




    Windows 10

    Windows 10

    Windows 10 Mobile



    11

    Import keys/secrets into the secure key storage

    Windows 10

    Windows 10 Mobile



    Windows 10




    12

    Destroy imported keys/secrets and any other keys/secrets in the secure key storage

    Windows 10

    Windows 10 Mobile



    Windows 10




    13

    Import X.509v3 certificates into the Trust Anchor Database




    Windows 10

    Windows 10

    Windows 10 Mobile



    14

    Remove imported X.509v3 certificates and any other X.509v3 certificates in the Trust Anchor Database

    Windows 10 Mobile

    Windows 10




    15

    Enroll the TOE in management

    Windows 10 Mobile

    Windows 10





    16

    Remove applications




    Windows 10

    Windows 10

    Windows 10 Mobile



    17

    Update system software




    Windows 10

    Windows 10

    Windows 10 Mobile



    18

    Install applications 




    Windows 10

    Windows 10

    Windows 10 Mobile



    19

    Remove Enterprise applications




    Windows 10

    Windows 10

    Windows 10 Mobile



    20

    Configure the Bluetooth trusted channel

    a. disable/enable the Discoverable mode (for BR/EDR)









    Windows 10

    Windows 10 Mobile






    b. change the Bluetooth device name







    Windows 10

    Windows 10 Mobile






    d. disable/enable Advertising (for LE),







    Windows 10

    Windows 10 Mobile



    21

    Enable/disable display notification in the locked state







    Windows 10

    Windows 10 Mobile



    22

    Enable/disable all data signaling over [USB hardware ports]




    Windows 10

    Windows 10 Mobile

    23

    Enable/disable [none, Assign personal Hotspot connections]




    Windows 10

    Windows 10

    Windows 10 Mobile



    24

    Enable/disable developer modes




    Windows 10

    Windows 10

    Windows 10 Mobile



    25

    Enable data-at rest protection

    Windows 10 Mobile

    Windows 10




    26

    Enable removable media’s data at rest protection

    Windows 10

    Windows 10




    28

    Wipe Enterprise data




    Windows 10

    Windows 10

    Windows 10 Mobile



    30

    Configure whether to allow a trusted channel if certificate validation is not possible

    Windows 10

    Windows 10 Mobile



    Windows 10




    31

    Enable/disable the cellular protocols used to connect to cellular network base stations




    Windows 10

    Windows 10 Mobile

    32

    Read audit logs kept by the TSF




    Windows 10




    33

    Configure certificate used to validate digitally signed applications




    Windows 10

    Windows 10

    Windows 10 Mobile



    34

    Approve exceptions for shared use of keys/secrets by multiple applications




    Windows 10

    Windows 10

    Windows 10 Mobile



    35

    Approve exceptions for destruction of keys/secrets by other applications

    Windows 10

    Windows 10 Mobile



    Windows 10




    36

    Configure the unlock banner




    Windows 10

    Windows 10

    Windows 10 Mobile



    37

    Configure the auditable items




    Windows 10




    38

    Retrieve TSF-software integrity verification values







    Windows 10

    Windows 10 Mobile



    39

    enable/disable [USB mass storage mode]







    Windows 10 Mobile

    40

    Enable/disable backup to remote system

    Windows 10

    Windows 10 Mobile



    Windows 10




    44

    Enable/disable location services




    Windows 10

    Windows 10

    Windows 10 Mobile


    1. Managing Audits


    This section contains the following Common Criteria SFRs:

    • Audit Data Generation (FAU_GEN.1), Selective Audit (FAU_SEL.1)

    • Extended: Audit Storage Protection (FAU_STG_EXT.1)

    • Specifications of Management Functions (FMT_SMF_EXT.1)
      1. Windows 10

        1. Audit Events


    The following required audits are described for FAU_GEN.1:

    Description

    Id

    Start-up and shutdown of the audit functions

    Security: 4608, 1100

    All administrative actions



    Startup and shutdown of the OS and kernel

    Security: 4608, 1100

    Insertion or removal of removable media

    Microsoft- Windows-Kernel-PnP/Device Configuration: 410



    Establishment of a synchronizing connection

    System: 36880

    Microsoft-Windows-CAPI2/Operational: 11



    Specifically defined auditable events from table 10



    Audit records reaching [assignment: integer value less than 100] percentage of audit capacity, [assignment: other auditable events derived from this profile

    Security: 1103

    Table 1: FAU_GEN.1 audits (AGD1: FAU_GEN.1)
    The following table correlates the set of administrative operations described in this document with their associated audits. Section FMT_SMF_EXT.1 has test procedures to produce these audits.

    Administrative Action

    Id

    1. configure password policy:

      1. minimum password length

      2. minimum password complexity

      3. maximum password lifetime

    IT Administrator:

    DeviceManagement-Enterprise-Diagnostics-Provider/Admin: 813


    Local Administrator:

    Security: 4739



    1. configure session locking policy:

      1. screen-lock enabled/disabled

      2. screen lock timeout

      3. number of authentication failures

    IT Administrator:

    DeviceManagement-Enterprise-Diagnostics-Provider/Admin: 813


    Local Administrator:

    Security: 4739



    1. enable/disable the VPN protection:

      1. across device

    [b. on a per-app basis

    c. no other method]

    Security:

    Enable: 4651, 5451

    Disable: 4655


    1. enable/disable [GPS, Wi-Fi, Bluetooth, mobile broadband]

    DeviceManagement-Enterprise-Diagnostics-Provider/Admin: 813

    1. enable/disable [camera, microphone]:

      1. across device [

    b. on a per-app basis



    Download 298.26 Kb.
    1   2   3   4   5   6   7   8   9   ...   60




    Download 298.26 Kb.

    Bosh sahifa
    Aloqalar

        Bosh sahifa



    Microsoft Windows Common Criteria Evaluation Microsoft Windows 10

    Download 298.26 Kb.