Ricoh Aficio MP 3352 Security Target - Page 61

Class FMT: Security management

Page 61 highlights

Page 60 of 91 FIA_USB.1.3 The TSF shall enforce the following rules governing changes to the user security attributes associated with subjects acting on the behalf of users: [assignment: none]. 6.1.5 Class FMT: Security management FMT_MSA.1(a)Management of security attributes Hierarchical to: No other components. Dependencies: [FDP_ACC.1 Subset access control, or FDP_IFC.1 Subset information flow control] FMT_SMR.1 Security roles FMT_SMF.1 Specification of Management Function FMT_MSA.1.1(a) The TSF shall enforce the [assignment: document access control SFP] to restrict the ability to [selection: query, modify, delete, [assignment: newly create]] the security attributes [assignment: security attributes in Table 26] to [assignment: the user roles with operation permission in Table 26]. Table 26 : User Roles for Security Attributes (a) Security Attributes Login user name of normal user for Basic Authentication Login user name of normal user for External Authentication Login user name of supervisor Login user name of MFP administrator Document data attribute Document user list [when document data attributes are (+PRT), (+SCN), (+CPY), and (+FAXOUT)] Operations Query, modify, delete, newly create Query Query, modify, delete, newly create Query, modify Newly create Query, modify Query No operation permitted User Roles with Operation Permission MFP administrator Normal user who owns the applicable login user name MFP administrator Supervisor MFP administrator MFP administrator who owns the applicable login user name Supervisor None No operation permitted None Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92

Page 60 of
91
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
FIA_USB.1.3
The TSF shall enforce the following rules governing changes to the user security attributes
associated with subjects acting on the behalf of users:
[assignment: none]
.
6.1.5
Class FMT: Security management
FMT_MSA.1(a)Management of security attributes
Hierarchical to:
No other components.
Dependencies:
[FDP_ACC.1 Subset access control, or
FDP_IFC.1 Subset information flow control]
FMT_SMR.1 Security roles
FMT_SMF.1 Specification of Management Function
FMT_MSA.1.1(a) The TSF shall enforce the
[assignment: document access control SFP]
to restrict the ability to
[selection: query, modify, delete, [assignment: newly create]]
the security attributes
[assignment: security attributes in Table 26]
to
[assignment: the user roles with operation
permission in Table 26]
.
Table 26 : User Roles for Security Attributes (a)
Security Attributes
Operations
User Roles
with Operation Permission
Query,
modify,
delete,
newly create
MFP administrator
Login user name of normal user
for Basic Authentication
Query
Normal user who owns the applicable
login user name
Login user name of normal user
for External Authentication
Query,
modify,
delete,
newly create
MFP administrator
Login user name of supervisor
Query,
modify
Supervisor
Newly create
MFP administrator
Query,
modify
MFP administrator who owns the
applicable login user name
Login user name of MFP administrator
Query
Supervisor
Document data attribute
No operation permitted
None
Document user list
[when document data attributes are
(+PRT), (+SCN), (+CPY), and
(+FAXOUT)]
No operation permitted
None