|
Protection of internal transfer of remediation information (user data). The evaluators verified that the TOE uses SSL to secure data transfers between the server and clients. The evaluators verified the information flow control security functional policy governing sever-to-client communications [SERVER_SFP] and that the only information that a Hercules® AVR Server will accept from any client machine is: (a) the identification of the client machine for authentication purposes when requesting a scheduled remediation, and (b) remediation status information during the course of a remediation session, in accordance with the TOE security function F.ENCRYPT and F.IACLIENT as defined in the Hercules® AVR ST.
|