Ricoh Aficio MP 3352 Security Target - Page 55

Table 19 : Additional Rules to Control Operations on Document Data and User Jobs

Page 55 highlights

Document data +FAXIN Delete Document data +FAXIN Read Document data +CPY Document data +CPY Document data +DSR Delete Read Delete Document data +DSR Read User jobs No setting of document data attribute Delete Normal user process Normal user process Normal user process Normal user process Normal user process Normal user process Normal user process Page 54 of 91 Not allowed. However, it is allowed for normal user process with login user name of normal user registered on document user list for document data. Not allowed. However, it is allowed for normal user process with login user name of normal user registered on document user list for document data. Not allowed. However, it is allowed for normal user process that created the document data. Not allowed. However, it is allowed for normal user process that created the document data. Not allowed. However, it is allowed for normal user process with login user name of normal user registered on document user list for document data. Not allowed. However, it is allowed for normal user process with login user name of normal user registered on document user list for document data. Not allowed. However, it is allowed for normal user process with login user name of normal user, which is the security attribute of user jobs. FDP_ACF.1.3(a) The TSF shall explicitly authorise access of subjects to objects based on the following additional rules: [assignment: rules to control operations among subjects and objects shown in Table 19]. Table 19 : Additional Rules to Control Operations on Document Data and User Jobs (a) Objects Document data Document data Document data Document Data Attributes +PRT +FAXIN +DSR Operations Subjects Delete Delete Delete MFP administrator process MFP administrator process MFP administrator process Rules to control Operations Allows. Allows. Allows. Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92

Page 54 of
91
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
Document
data
+FAXIN
Delete
Normal user
process
Not allowed. However, it is allowed for
normal user process with login user
name of normal user registered on
document user list for document data.
Document
data
+FAXIN
Read
Normal user
process
Not allowed. However, it is allowed for
normal user process with login user
name of normal user registered on
document user list for document data.
Document
data
+CPY
Delete
Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+CPY
Read
Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+DSR
Delete
Normal user
process
Not allowed. However, it is allowed for
normal user process with login user
name of normal user registered on
document user list for document data.
Document
data
+DSR
Read
Normal user
process
Not allowed. However, it is allowed for
normal user process with login user
name of normal user registered on
document user list for document data.
User jobs
No setting of
document data
attribute
Delete
Normal user
process
Not allowed. However, it is allowed for
normal user process with login user
name of normal user, which is the
security attribute of user jobs.
FDP_ACF.1.3(a) The TSF shall explicitly authorise access of subjects to objects based on the following
additional rules:
[assignment: rules to control operations among subjects and objects
shown in Table 19]
.
Table 19 : Additional Rules to Control Operations on Document Data and User Jobs (a)
Objects
Document Data
Attributes
Operations
Subjects
Rules to control Operations
Document
data
+PRT
Delete
MFP
administrator
process
Allows.
Document
data
+FAXIN
Delete
MFP
administrator
process
Allows.
Document
data
+DSR
Delete
MFP
administrator
process
Allows.