[Fed-Talk] Common Criteria Tools (was Re: NIST SP 80-0-53 Question (AU-7))
[Fed-Talk] Common Criteria Tools (was Re: NIST SP 80-0-53 Question (AU-7))
- Subject: [Fed-Talk] Common Criteria Tools (was Re: NIST SP 80-0-53 Question (AU-7))
- From: "Dan O'Donnell" <email@hidden>
- Date: Mon, 22 Jan 2007 11:35:39 -0800
- Thread-topic: Common Criteria Tools (was Re: NIST SP 80-0-53 Question (AU-7))
Ten days ago at MacWorld I gave a presentation on Common Criteria Tools for
OS X.
I'm currently making some enhancements to the Keynote presentation and will
make it available on my iDisk as soon as those changes are complete.
Dan O'Donnell
On 1/22/07 11:26 AM, "email@hidden"
<email@hidden> wrote:
> Date: Mon, 22 Jan 2007 13:44:11 -0500
> From: "Shawn A. Geddis" <email@hidden>
> Subject: Re: [Fed-Talk] NIST SP 80-0-53 Question (AU-7)
> To: "Grosman, Louis (NIH/NHGRI) [C]" <email@hidden>
> Cc: email@hidden
> Message-ID: <email@hidden>
> Content-Type: text/plain; charset="us-ascii"
>
> On Jan 22, 2007, at 1:12 PM, Grosman, Louis (NIH/NHGRI) [C] wrote:
>> At NHGRI we are using Common Criteria 1.01 on our 10.3.9 Server -
>> http://www.apple.com/support/downloads/commoncriteriatools.html
>>
>> On our 10.4 servers (which is all of our other Mac servers now),
>>
>> We are using the 10.4 Common Criteria tools - http://www.apple.com/
>>
>> support/downloads/commoncriteriatoolsfor104.html.
>>
>> NIST SP800-53, Recommended Security Controls for Federal Information
>> Systems, security control AU-7 (AUDIT REDUCTION AND REPORT
>> GENERATION) requires that the information system provides an audit
>> reduction and report generation capability.
>>
>> Are you aware of any products that can access the logging
>> information collected by the Common Criteria Tools and produce
>> useful and meaningful reports?
>>
>> Thanks very much.
>>
<snip>
>
> Mr. Grosman,
>
>
> The "Auditing" subsystem on Mac OS X is based on SUN's C2/BSM (Basic
> Security Module).
>
> The accompanying Admin Guide for the Common Criteria Tools indicates
> the CLI commands and tools used to perform the reduction and printing/
> reporting of the desired audit records.
<snip>
> - Shawn
> ___________________________________________
> Shawn Geddis
> Security Consulting Engineer
> Apple Enterprise Division (Public & Private Sector)
--------------------
This email message is for the sole use of the intended recipient(s) and
may contain privileged information. Any unauthorized review, use,
disclosure or distribution is prohibited. If you are not the intended
recipient, please contact the sender by reply email and destroy all copies
of the original message.
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden