Does TSF include administrator?



When a requirement says "the TSF shall...", is it sufficient that the
requirement is (partially) met by administrator or operator procedures?
For example, FDP_ITC.2.4 says the TSF shall ensure that security
attributes imported  are interpreted as intended by the source. Is the
requirement met even if the local administrator had to manually "talk"
to the administrator of another system and manually map a foreign label
to a local label? This procedure would of course be documented in the
administrator guidance. I notice that the definition of TOE includes the
administrator guidance, but the definition of TSF does not.



Date Index | Thread Index | Problems or questions? Contact list-master@nist.gov