Ricoh Aficio MP 3352 Security Target - Page 56

Table 21 : Rule to Control Operations on MFP Applications b

Page 56 highlights

User jobs No setting of document data attribute Delete MFP administrator process Allows. Page 55 of 91 FDP_ACF.1.4(a) The TSF shall explicitly deny access of subjects to objects based on the following additional rules: [assignment: deny the operations on the document data and user jobs in case of supervisor process or RC Gate process]. FDP_ACF.1(b) Security attribute-based access control Hierarchical to: No other components. Dependencies: FDP_ACC.1 Subset access control FMT_MSA.3 Static attribute initialisation FDP_ACF.1.1(b) The TSF shall enforce the [assignment: TOE function access control SFP] to objects based on the following: [assignment: subjects or objects, and their corresponding security attributes shown in Table 20]. Table 20 : Subjects, Objects and Security Attributes (b) Category Subject Subjects or Objects Normal user process Object Supervisor process RC Gate process MFP application Security Attributes - Login user name of normal user - Available function list - User role - User role - User role - Function type FDP_ACF.1.2(b) The TSF shall enforce the following rules to determine if an operation among controlled subjects and controlled objects is allowed: [assignment: rule to control operations among objects and subjects shown in Table 21]. Table 21 : Rule to Control Operations on MFP Applications (b) Object Operation Subject Rule to control Operations MFP application Execute Normal user process Allows executing MFP application which MFP administrator allowed in available function list for normal user process. FDP_ACF.1.3(b) The TSF shall explicitly authorise access of subjects to objects based on the following additional rules: [assignment: rules that the Fax Reception Function operated using administrator permission is surely permitted]. Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92

Page 55 of
91
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
User jobs
No setting of
document data
attribute
Delete
MFP
administrator
process
Allows.
FDP_ACF.1.4(a) The TSF shall explicitly deny access of subjects to objects based on the following additional
rules:
[assignment: deny the operations on the document data and user jobs in case of
supervisor process or RC Gate process]
.
FDP_ACF.1(b) Security attribute-based access control
Hierarchical to:
No other components.
Dependencies:
FDP_ACC.1 Subset access control
FMT_MSA.3 Static attribute initialisation
FDP_ACF.1.1(b) The TSF shall enforce the
[assignment: TOE function access control SFP]
to objects based
on the following:
[assignment: subjects or objects, and their corresponding security
attributes shown in Table 20]
.
Table 20 : Subjects, Objects and Security Attributes (b)
Category
Subjects or Objects
Security Attributes
Normal user process
- Login user name of normal user
- Available function list
- User role
Supervisor process
- User role
Subject
RC Gate process
- User role
Object
MFP application
- Function type
FDP_ACF.1.2(b) The TSF shall enforce the following rules to determine if an operation among controlled
subjects and controlled objects is allowed:
[assignment: rule to control operations among
objects and subjects shown in Table 21]
.
Table 21 : Rule to Control Operations on MFP Applications (b)
Object
Operation
Subject
Rule to control Operations
MFP application
Execute
Normal user process
Allows executing MFP application
which MFP administrator allowed in
available function list for normal user
process.
FDP_ACF.1.3(b) The TSF shall explicitly authorise access of subjects to objects based on the following
additional rules:
[assignment: rules that the Fax Reception Function operated using
administrator permission is surely permitted]
.