Ricoh Aficio MP 2852 Security Target - Page 54

Table 18 : Rules to Control Operations on Document Data and User Jobs

Page 54 highlights

Page 53 of 91 FDP_ACF.1.1(a) The TSF shall enforce the [assignment: document access control SFP] to objects based on the following: [assignment: subjects or objects, and their corresponding security attributes shown in Table 1766]. Table 176 : Subjects, Objects and Security Attributes (a) Category Subject Subjects or Objects Normal user process Subject Subject Subject Object MFP administrator process Supervisor process RC Gate process Document data Object User job Security Attributes - Login user name of normal user - User role - User role - User role - User role - Document data attribute - Document user list - Login user name of normal user FDP_ACF.1.2(a) The TSF shall enforce the following rules to determine if an operation among controlled subjects and controlled objects is allowed: [assignment: rules to control operations among subjects and objects shown in Table 18]. Table 18 : Rules to Control Operations on Document Data and User Jobs (a) Objects Document data Document data Document data Document data Document data Document data Document Data Attributes +PRT Operations Subjects Delete Normal user process +PRT Read Normal user process +SCN Delete Normal user process +SCN Read Normal user process +FAXOUT Delete Normal user process +FAXOUT Read Normal user process Rules to control Operations Not allowed. However, it is allowed for normal user process that created the document data. Not allowed. However, it is allowed for normal user process that created the document data. Not allowed. However, it is allowed for normal user process that created the document data. Not allowed. However, it is allowed for normal user process that created the document data. Not allowed. However, it is allowed for normal user process that created the document data. Not allowed. However, it is allowed for normal user process that created the document data. Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92

Page 53 of
91
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
FDP_ACF.1.1(a) The TSF shall enforce the
[assignment: document access control SFP]
to objects based on the
following:
[assignment: subjects or objects, and their corresponding security attributes
shown in Table 1766]
.
Table 176 : Subjects, Objects and Security Attributes (a)
Category
Subjects or Objects
Security Attributes
Subject
Normal user process
- Login user name of normal user
- User role
Subject
MFP administrator process
- User role
Subject
Supervisor process
- User role
Subject
RC Gate process
- User role
Object
Document data
- Document data attribute
- Document user list
Object
User job
- Login user name of normal user
FDP_ACF.1.2(a) The TSF shall enforce the following rules to determine if an operation among controlled
subjects and controlled objects is allowed:
[assignment: rules to control operations among
subjects and objects shown in Table 18]
.
Table 18 : Rules to Control Operations on Document Data and User Jobs (a)
Objects
Document Data
Attributes
Operations
Subjects
Rules to control Operations
Document
data
+PRT
Delete
Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+PRT
Read
Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+SCN
Delete
Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+SCN
Read
Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+FAXOUT
Delete
Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+FAXOUT
Read
Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.