Skip to content

Duplicate audit event list and format EAs #12

Description

@lmitcheld

The TSS and Guidance EAs for FAU_GEN.1.1 require that both the TSS and the administrative guide list all of the auditable events and that the evaluator check that every audit event type mandated buy the ST is described. The TSS and Guidance EAs for FAU_GEN.1.2 require the same for the audit data format.

Having the same information specified in two different places is a bit duplicative and could lead to inconsistencies if not kept up to date. This issue was raised in the NDcPP a while ago and the decision was made to require the information only in the guidance documentation.

Am raising this for your consideration to reduce duplication of documentation and effort by having the audit information completely specified in one place.

Note: This same issue exists in the MDM PP; I have submitted the same issue for it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions