Ricoh Aficio MP 2851 Security Target - Page 30

Organisational Security Policies and 3.3 Assumptions.

Page 30 highlights

Page 30 of 81 Table 3: Relationship between security environment and security objectives TOE security Environment A.ADMIN A.SUPERVISOR A.NETWORK T.ILLEGAL_USE T.UNAUTH_ACCESS T.ABUSE_SEC_MNG T.SALVAGE T.TRANSIT T.FAX_LINE P.SOFTWARE Security objectives O.AUDIT O.I&A O.DOC_ACC O.MANAGE O.MEM.PROTECT O.NET.PROTECT O.GENUINE O.LINE_PROTECT OE.ADMIN OE.SUPERVISOR OE.NETWORK v vv vv v vv v v v v v v v v v 4.3.2 Tracing Justification The following are the rationale for each security objectives being appropriate to satisfy "3.1 Threats", "3.2 Organisational Security Policies" and "3.3 Assumptions". A.ADMIN (Assumptions for administrators) As specified by A.ADMIN, administrators shall have sufficient knowledge to operate the TOE securely in the roles assigned to them and instruct general users to operate the TOE securely also. Additionally, administrators are unlikely to abuse their permissions. As specified by OE.ADMIN, the responsible manager of the MFP shall select trusted persons as administrators and instruct them on their administrator roles. Once instructed, administrators thenshall instruct general users, familiarising them with the compliance rules for secure TOE operation as defined in the administrator guidance for the TOE. Therefore, A.ADMIN is upheld. A.SUPERVISOR (Assumptions for supervisors) As specified by A.SUPERVISOR, supervisors shall have sufficient knowledge to operate the TOE securely in the roles assigned to them, and be unlikely to abuse their permissions. As specified by OE.SUPERVISOR, the responsible manager of the MFP shall select trusted persons as supervisors and instruct them on the role of supervisor. Therefore, A.SUPERVISOR is upheld. Copyright (c) 2010 RICOH COMPANY, LTD. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81

Page 30 of 81
Copyright (c) 2010 RICOH COMPANY, LTD. All Rights Reserved.
Table 3: Relationship between security environment and security objectives
TOE
security
Environment
Security objectives
A.ADMIN
A.SUPERVISOR
A.NETWORK
T.ILLEGAL_USE
T.UNAUTH_ACCESS
T.ABUSE_SEC_MNG
T.SALVAGE
T.TRANSIT
T.FAX_LINE
P.SOFTWARE
O.AUDIT
v
v
v
v
v
O.I&A
v
v
v
O.DOC_ACC
v
O.MANAGE
v
O.MEM.PROTECT
v
O.NET.PROTECT
v
O.GENUINE
v
O.LINE_PROTECT
v
OE.ADMIN
v
OE.SUPERVISOR
v
OE.NETWORK
v
4.3.2
Tracing Justification
The following are the rationale for each security objectives being appropriate to satisfy "3.1 Threats", "3.2
Organisational Security Policies" and "3.3 Assumptions".
A.ADMIN
(Assumptions for administrators)
As specified by A.ADMIN, administrators shall have sufficient knowledge to operate the TOE securely in
the roles assigned to them and instruct general users to operate the TOE securely also. Additionally,
administrators are unlikely to abuse their permissions.
As specified by OE.ADMIN, the responsible manager of the MFP shall select trusted persons as
administrators and instruct them on their administrator roles. Once instructed, administrators then shall
instruct general users, familiarising them with the compliance rules for secure TOE operation as defined in
the administrator guidance for the TOE. Therefore, A.ADMIN is upheld.
A.SUPERVISOR
(Assumptions for supervisors)
As specified by A.SUPERVISOR, supervisors shall have sufficient knowledge to operate the TOE securely
in the roles assigned to them, and be unlikely to abuse their permissions.
As specified by OE.SUPERVISOR, the responsible manager of the MFP shall select trusted persons as
supervisors and instruct them on the role of supervisor. Therefore, A.SUPERVISOR is upheld.