-
Notifications
You must be signed in to change notification settings - Fork 3
null auditable event disclaimer in functional package appendix #130
Description
The TLS FP has templated preamble text to both the auditable events for mandatory SFRs and the auditable events for sel-based SFRs (B.1). The latter is missing the following sentence which is in the former, and should also be included per NIAP TD0912:
Note that, if "None" is not selected in the "Auditable Events" column, it should not be selected in the "Additional Audit Record Contents" column. Likewise, if "None" is selected in the "Auditable Events" column, it should also be selected in the "Additional Audit Record Contents" column.
Since the auditable events table for sel-based SFRs appears to be auto-populated in the FP (the only audit table in the TLS xml is the mandatory one), along with its introductory text, it's unclear what is populating the text and whether it is possible for the editor to add this missing sentence, or if the transforms needs to be updated to accommodate this.