Ricoh Aficio MP 2851 Security Target - Page 36

Login Outcome: Success/Failure - default login

Page 36 highlights

Functional requirements FIA_UAU.2 FIA_UAU.7 FIA_UID.2 FIA_USB.1 FMT_MSA.1 FMT_MSA.3 FMT_MTD.1 Page 36 of 81 Actions which should be auditable Minimal: Unsuccessful use of the authentication mechanism; Basic: All use of the authentication mechanism. None a) Minimal: Unsuccessful use of the user identification mechanism, including the user identity provided; b) Basic: All use of the user identification mechanism, including the user identity provided. a) Minimal: Unsuccessful binding of user security attributes to a subject (e.g. creation of a subject). b) Basic: Success and failure of binding of user security attributes to a subject (e.g. success or failure to create a subject). a) Basic: All modifications of the values of security attributes. a) Basic: Modifications of the default setting of permissive or restrictive rules. b) Basic: All modifications of the initial values of security attributes. a) Basic: All modifications to the values of TSF data. Auditable events of TOE 3. Changing administrator authentication information (Outcome: Success/Failure) 4. Changing supervisor authentication information (Outcome: Success/Failure) Basic 1. Login (Outcome: Success/Failure) b) Basic 1. Login (Outcome: Success/Failure) b) Basic 1. Login (Outcome: Success/Failure) 1. Adding and deleting administrator roles 2. Changing document data ACL Auditable events not recorded. 1. Newly creating authentication information of general users. 2. Changing authentication information of general users. 3. Deleting authentication information of general users. 4. Changing administrator Authentication information. 5. Changing supervisor Authentication information. Copyright (c) 2010 RICOH COMPANY, LTD. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81

Page 36 of 81
Copyright (c) 2010 RICOH COMPANY, LTD. All Rights Reserved.
Functional requirements
Actions which should be auditable
Auditable events of TOE
3. Changing administrator
authentication information (Outcome:
Success/Failure)
4. Changing supervisor authentication
information (Outcome:
Success/Failure)
FIA_UAU.2
Minimal: Unsuccessful use of the
authentication mechanism;
Basic: All use of the authentication
mechanism.
Basic
1. Login (Outcome: Success/Failure)
FIA_UAU.7
None
-
FIA_UID.2
a) Minimal: Unsuccessful use of the
user identification mechanism,
including the user identity provided;
b) Basic: All use of the user
identification mechanism, including
the user identity provided.
b) Basic
1. Login (Outcome: Success/Failure)
FIA_USB.1
a) Minimal: Unsuccessful binding of
user security attributes to a subject
(e.g. creation of a subject).
b) Basic: Success and failure of
binding of user security attributes to a
subject (e.g. success or failure to create
a subject).
b) Basic
1. Login (Outcome: Success/Failure)
FMT_MSA.1
a) Basic: All modifications of the
values of security attributes.
<Individually-defined auditable
events>
1. Adding and deleting administrator
roles
2. Changing
document data ACL
FMT_MSA.3
a) Basic: Modifications of the default
setting of permissive or restrictive
rules.
b) Basic: All modifications of the
initial values of security attributes.
Auditable events not recorded.
FMT_MTD.1
a) Basic: All modifications to the
values of TSF data.
<Individually-defined auditable
events>
1. Newly creating authentication
information of general users.
2. Changing authentication
information of general users.
3. Deleting authentication
information of general users.
4. Changing administrator
Authentication information.
5. Changing supervisor
Authentication information.