FPT_RVM.1     Non-bypassability of the TSP

User application notes

In order to obtain the equivalent of a reference monitor, this component must be used with either FPT_SEP.2 (SFP domain separation) or FPT_SEP.3 (Complete reference monitor), and ADV_INT.3 (Minimisation of complexity). Further, if complete reference mediation is required, the components from Class FDP User data protection must cover all objects.