Ricoh Aficio MP C3001 Security Target - Page 63

Table 26 : User Roles for Security Attributes a, Security Attributes, Operations, User Roles,

Page 63 highlights

Page 62 of 93 Dependencies: [FDP_ACC.1 Subset access control, or FDP_IFC.1 Subset information flow control] FMT_SMR.1 Security roles FMT_SMF.1 Specification of Management Function FMT_MSA.1.1(a) The TSF shall enforce the [assignment: document access control SFP] to restrict the ability to [selection: query, modify, delete, [assignment: newly create]] the security attributes [assignment: security attributes in Table 26] to [assignment: the user roles with operation permission in Table 26]. Table 26 : User Roles for Security Attributes (a) Security Attributes Login user name of normal user for Basic Authentication Login user name of normal user for External Authentication Login user name of supervisor Login user name of MFP administrator Document data attribute Document user list [when document data attributes are (+PRT), (+SCN), (+CPY), and (+FAXOUT)] Document user list [when document data attribute is (+DSR)] Document user list [when document data attribute is (+FAXIN)] Operations Query, modify, delete, newly create Query Query, modify, delete, newly create Query, modify Newly create Query, modify Query No operation permitted User Roles with Operation Permission MFP administrator Normal user who owns the applicable login user name MFP administrator Supervisor MFP administrator MFP administrator who owns the applicable login user name Supervisor - No operation permitted - Query, modify Query, modify MFP administrator, applicable normal user who stored the document data MFP administrator -: No user roles are permitted for operations by the TOE. Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94

Page 62 of
93
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
Dependencies:
[FDP_ACC.1 Subset access control, or
FDP_IFC.1 Subset information flow control]
FMT_SMR.1 Security roles
FMT_SMF.1 Specification of Management Function
FMT_MSA.1.1(a) The TSF shall enforce the
[assignment: document access control SFP]
to restrict the ability to
[selection: query, modify, delete, [assignment: newly create]]
the security attributes
[assignment: security attributes in Table 26]
to
[assignment: the user roles with operation
permission in Table 26]
.
Table 26 : User Roles for Security Attributes (a)
Security Attributes
Operations
User Roles
with Operation Permission
Query,
modify,
delete,
newly create
MFP administrator
Login user name of normal user
for Basic Authentication
Query
Normal user who owns the applicable
login user name
Login user name of normal user
for External Authentication
Query,
modify,
delete,
newly create
MFP administrator
Login user name of supervisor
Query,
modify
Supervisor
Newly create
MFP administrator
Query,
modify
MFP administrator who owns the
applicable login user name
Login user name of MFP administrator
Query
Supervisor
Document data attribute
No operation permitted
-
Document user list
[when
document
data
attributes
are
(+PRT),
(+SCN),
(+CPY),
and
(+FAXOUT)]
No operation permitted
-
Document user list
[when document data attribute is (+DSR)]
Query,
modify
MFP administrator,
applicable normal user who stored the
document data
Document user list
[when
document
data
attribute
is
(+FAXIN)]
Query,
modify
MFP administrator
-: No user roles are permitted for operations by the TOE.