6.12 Inter-TSF user data confidentiality transfer protection (FDP_UCT)

Family behaviour

This family defines the requirements for ensuring the confidentiality of user data when it is transferred using an external channel between distinct TOEs or users on distinct TOEs.

Component levelling

In FDP_UCT.1 Basic data exchange confidentiality, the goal is to provide protection from disclosure of user data while in transit.

Management: FDP_UCT.1

There are no management activities foreseen for this component.

Audit: FDP_UCT.1

The following events should be auditable if FAU_GEN Security audit data generation is included in the PP/ST.

a)    Minimal: The identity of any user or subject using the data exchange mechanisms.

b)    Basic: The identity of any unauthorised user or subject attempting to use the data exchange mechanisms.

c)    Basic: A reference to the names or other indexing information useful in identifying the user data that was transmitted or received. This could include security attributes associated with the information.