6.11 Stored data integrity (FDP_SDI)

Family behaviour

This family provides requirements that address protection of user data while it is stored within the TSC. Integrity errors may affect user data stored in memory, or in a storage device. This family differs from FDP_ITT Internal TOE transfer which protects the user data from integrity errors while being transferred within the TOE.

Component levelling

FDP_SDI.1 Stored data integrity monitoring requires that the SF monitor user data stored within the TSC for identified integrity errors.

FDP_SDI.2 Stored data integrity monitoring and action adds the additional capability to the first component by allowing for actions to be taken as a result of an error detection.

Management: FDP_SDI.1

There are no management activities foreseen for this component.

Management: FDP_SDI.2

The following actions could be considered for the management functions in FMT Management:

a)    The actions to be taken upon the detection of an integrity error could be configurable.

Audit: FDP_SDI.1

The following events should be auditable if FAU_GEN Security audit data generation is included in the PP/ST:

a)    Minimal: Successful attempts to check the integrity of user data, including an indication of the results of the check.

b)    Basic: All attempts to check the integrity of user data, including an indication of the results of the check, if performed.

c)    Detailed: The type of integrity error that occurred.

Audit: FDP_SDI.2

The following events should be auditable if FAU_GEN Security audit data generation is included in the PP/ST:

a)    Minimal: Successful attempts to check the integrity of user data, including an indication of the results of the check.

b)    Basic: All attempts to check the integrity of user data, including an indication of the results of the check, if performed.

c)    Detailed: The type of integrity error that occurred.

d)    Detailed: The action taken upon detection of an integrity error.