FMT_SAE.1     Time-limited authorisation

Operations

Assignment:

For FMT_SAE.1.1, the PP/ST author should provide the list of security attributes for which expiration is to be supported. An example of such an attribute might be a user's security clearance.

In FMT_SAE.1.1 the PP/ST author should specify the roles that are allowed to modify the security attributes in the TSF. The possible roles are specified in FMT_SMR.1.

For FMT_SAE.1.2, the PP/ST author should provide a list of actions to be taken for each security attribute when it expires. An example might be that the user's security clearance, when it expires, is set to the lowest allowable clearance on the TOE. If immediate revocation is desired by the PP/ST, the action "immediate revocation" should be specified.