Ricoh Aficio MP C3001 Security Target - Page 73

O.DOC.NO_ALT Protection of document alteration, O.FUNC.NO_ALT Protection of user job alteration

Page 73 highlights

Page 72 of 93 is thus restricted to perform each operation. FMT_MSA.3(a) surely sets the restrictive value to the security attributes of document data (object) when document data are generated. By satisfying FDP_ACC.1(a), FDP_ACF.1(a), FDP_RIP.1, FTP_ITC.1, FMT_MSA.1(a) and FMT_MSA.3(a), which are the security functional requirements for these countermeasures, O.DOC.NO_DIS is fulfilled. O.DOC.NO_ALT Protection of document alteration O.DOC.NO_ALT is the security objective to prevent the documents from unauthorised alteration by persons without a login user name, or by persons with a login user name but without an access permission to the document. To fulfil this security objective, it is required to implement the following countermeasures. (1) Specify and implement the access control to document data. FDP_ACC.1(a) and FDP_ACF.1(a) allow the following persons to delete document data (there is no "editing operation" of document data) according to the document data attributes: the normal user who generated the document data, the normal user who is registered in the document user list of the document data, and the MFP administrator. The supervisor and RC Gate are not allowed to delete document data. (2) Prevent deleting the deleted documents, temporary documents and their fragments. Deleted documents, temporary documents and their fragments are prevented from being used by FDP_RIP.1. (3) Use trusted channels for sending or receiving document data. The document data sent and received by the TOE via the LAN interface are protected by FTP_ITC.1. (4) Management of the security attributes. FMT_MSA.1(a) specifies the available operations (newly create, query, modify and delete) on the login user name, and available operations (query and modify) on the document user list, and a specified user is thus restricted to perform each operation. FMT_MSA.3(a) surely sets the restrictive value to the security attributes of document data (object) when the document data are generated. By satisfying FDP_ACC.1(a), FDP_ACF.1(a), FDP_RIP.1, FTP_ITC.1, FMT_MSA.1(a) and FMT_MSA.3(a), which are the security functional requirements for these countermeasures, O.DOC.NO_ALT is fulfilled. O.FUNC.NO_ALT Protection of user job alteration O.FUNC.NO_ALT is the security objective to prevent the user jobs from unauthorised alteration by persons without a login user name, or by persons with a login user name but without an access permission to the user job. To fulfil this security objective, it is required to implement the following countermeasures. (1) Specify and implement the access control to user jobs. FDP_ACC.1(a) and FDP_ACF.1(a) allow the MFP administrator to delete user jobs, and the normal user with the permission to delete the applicable user job. The supervisor and RC Gate are not allowed to delete user jobs. Deletion is the only modification operation on this TOE's user jobs. (2) Use trusted channels for sending or receiving user jobs. The user jobs sent and received by the TOE via the LAN are protected by FTP_ITC.1. Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94

Page 72 of
93
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
is thus restricted to perform each operation.
FMT_MSA.3(a) surely sets the restrictive value to the security attributes of document data (object)
when document data are generated.
By
satisfying
FDP_ACC.1(a),
FDP_ACF.1(a),
FDP_RIP.1,
FTP_ITC.1,
FMT_MSA.1(a)
and
FMT_MSA.3(a), which are the security functional requirements for these countermeasures, O.DOC.NO_DIS
is fulfilled.
O.DOC.NO_ALT Protection of document alteration
O.DOC.NO_ALT is the security objective to prevent the documents from unauthorised alteration by persons
without a login user name, or by persons with a login user name but without an access permission to the
document. To fulfil this security objective, it is required to implement the following countermeasures.
(1)
Specify and implement the access control to document data.
FDP_ACC.1(a) and FDP_ACF.1(a) allow the following persons to delete document data (there is no
"editing operation" of document data) according to the document data attributes: the normal user who
generated the document data, the normal user who is registered in the document user list of the
document data, and the MFP administrator. The supervisor and RC Gate are not allowed to delete
document data.
(2)
Prevent deleting the deleted documents, temporary documents and their fragments.
Deleted documents, temporary documents and their fragments are prevented from being used by
FDP_RIP.1.
(3)
Use trusted channels for sending or receiving document data.
The document data sent and received by the TOE via the LAN interface are protected by FTP_ITC.1.
(4)
Management of the security attributes.
FMT_MSA.1(a) specifies the available operations (newly create, query, modify and delete) on the login
user name, and available operations (query and modify) on the document user list, and a specified user
is thus restricted to perform each operation.
FMT_MSA.3(a) surely sets the restrictive value to the security attributes of document data (object)
when the document data are generated.
By
satisfying
FDP_ACC.1(a),
FDP_ACF.1(a),
FDP_RIP.1,
FTP_ITC.1,
FMT_MSA.1(a)
and
FMT_MSA.3(a),
which
are
the
security
functional
requirements
for
these
countermeasures,
O.DOC.NO_ALT is fulfilled.
O.FUNC.NO_ALT Protection of user job alteration
O.FUNC.NO_ALT is the security objective to prevent the user jobs from unauthorised alteration by persons
without a login user name, or by persons with a login user name but without an access permission to the user
job. To fulfil this security objective, it is required to implement the following countermeasures.
(1)
Specify and implement the access control to user jobs.
FDP_ACC.1(a) and FDP_ACF.1(a) allow the MFP administrator to delete user jobs, and the normal
user with the permission to delete the applicable user job. The supervisor and RC Gate are not allowed
to delete user jobs. Deletion is the only modification operation on this TOE's user jobs.
(2)
Use trusted channels for sending or receiving user jobs.
The user jobs sent and received by the TOE via the LAN are protected by FTP_ITC.1.