Ricoh Aficio MP 6001 SP Security Target - Page 29

Conformance Claim Rationale

Page 29 highlights

2600.1-SMI conformant Page 28 of 87 2.4 Conformance Claim Rationale 2.4.1 Consistency Claim with TOE Type in PP The targeted product type by the PP is the Hardcopy devices (hereafter, HCDs). The HCDs consist of the scanner device and print device, and have the interface to connect telephone line. The HCDs combine these devices and equip one or more functions of Copy Function, Scanner Function, Printer Function or Fax Function. The Document Server Function is also available when installing the non-volatile memory medium, such as hard disk drive, as additional equipments. The MFP is the type of this TOE. The MFP has the devices the HCDs have, and equips the functions that HCDs equip including the additional equipments. Therefore, this TOE type is consistent with the TOE type in the PP. 2.4.2 Consistency Claim with Security Problems and Security Objectives in PP Defining all security problems in the PP, P.STORAGE_ENCRYPTION was added to the security problem definitions in chapter 3. Defining all security objectives in the PP, O.STORAGE.ENCRYPTED was added to the security objectives in chapter 4. P.STORAGE_ENCRYPTION and O.STORAGE.ENCRYPTED encrypt data on the HDD, and satisfy both other organisational security policies in the PP and security objectives of the TOE. Therefore, the security problems and security objectives in this ST are consistent with the ones in the PP. Although the PP is written in English, the security problem definitions in chapter 3 and security objectives in chapter 4 are translated from English PP into Japanese. In translating into Japanese, if the literal translation of the PP was judged to make it difficult for readers to understand the PP, the translation was made easily comprehensible, however, its description is not deviated from the requirements of the PP conformance. Also, the description is neither increased nor decreased. 2.4.3 Consistency Claim with Security Requirements in PP The SFRs for this TOE consist of those found in the Common Security Functional Requirements and SFR Packages 2600.1-PRT, 2600.1-SCN, 2600.1-CPY, 2600.1-FAX, 2600.1-DSR, and 2600.1-SMI, and conform to the PP. FAU_STG.1, FAU_STG.4, FAU_SAR.1, and FAU_SAR.2 are added according to PP APPLICATION NOTE7 in order for the TOE to maintain and manage the audit logs. For the authentication function of the TOE, FIA_AFL.1, FIA_UAU.7, and FIA_SOS.1 are added according to PP APPLICATION NOTE36. For the ownership of the received fax documents, the TOE has the characteristic that the ownership of the document is assigned to the intended user. This is according to PP APPLICATION NOTE 93. Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88

Page 28 of
87
2600.1-SMI conformant
2.4
Conformance Claim Rationale
2.4.1
Consistency Claim with TOE Type in PP
The targeted product type by the PP is the Hardcopy devices (hereafter, HCDs). The HCDs consist of the
scanner device and print device, and have the interface to connect telephone line. The HCDs combine these
devices and equip one or more functions of Copy Function, Scanner Function, Printer Function or Fax
Function. The Document Server Function is also available when installing the non-volatile memory medium,
such as hard disk drive, as additional equipments.
The MFP is the type of this TOE. The MFP has the devices the HCDs have, and equips the functions that
HCDs equip including the additional equipments. Therefore, this TOE type is consistent with the TOE type
in the PP.
2.4.2
Consistency Claim with Security Problems and Security Objectives in PP
Defining all security problems in the PP, P.STORAGE_ENCRYPTION was added to the security problem
definitions in chapter 3.
Defining all security objectives in the PP, O.STORAGE.ENCRYPTED was added to the security objectives
in chapter 4. P.STORAGE_ENCRYPTION and O.STORAGE.ENCRYPTED encrypt data on the HDD, and
satisfy both other organisational security policies in the PP and security objectives of the TOE. Therefore,
the security problems and security objectives in this ST are consistent with the ones in the PP.
Although the PP is written in English, the security problem definitions in chapter 3 and security objectives in
chapter 4 are translated from English PP into Japanese. In translating into Japanese, if the literal translation
of the PP was judged to make it difficult for readers to understand the PP, the translation was made easily
comprehensible, however, its description is not deviated from the requirements of the PP conformance. Also,
the description is neither increased nor decreased.
2.4.3
Consistency Claim with Security Requirements in PP
The SFRs for this TOE consist of those found in the Common Security Functional Requirements and SFR
Packages 2600.1-PRT, 2600.1-SCN, 2600.1-CPY, 2600.1-FAX, 2600.1-DSR, and 2600.1-SMI, and conform
to the PP.
FAU_STG.1, FAU_STG.4, FAU_SAR.1, and FAU_SAR.2 are added according to PP APPLICATION
NOTE7 in order for the TOE to maintain and manage the audit logs.
For the authentication function of the TOE, FIA_AFL.1, FIA_UAU.7, and FIA_SOS.1 are added according
to PP APPLICATION NOTE36.
For the ownership of the received fax documents, the TOE has the characteristic that the ownership of the
document is assigned to the intended user. This is according to PP APPLICATION NOTE 93.
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.