Ricoh Aficio MP 3350B Security Target - Page 48

Administrator Role].

Page 48 highlights

Page 48 of 83 associated with subjects acting on the behalf of users: [assignment: Administrators can add their own assigned Administrator Roles to other Administrators, and can delete their own Administrator Roles. However, if deleting the Administrator Role makes no Administrator covers that Administrator Role, it is not allowed to delete the Administrator Role]. 6.1.5 Class FMT: Security management FMT_MSA.1 Management of security attributes Hierarchical to: No other components. Dependencies: [FDP_ACC.1 Subset access control, or FDP_IFC.1 Subset information flow control] FMT_SMR.1 Security roles FMT_SMF.1 Specification of Management Functions FMT_MSA.1.1 The TSF shall enforce the [assignment: MFP access control SFP] to restrict the ability to [selection: query, modify, delete, [assignment: newly create, change, add]] the security attributes [assignment: security attributes in Table 17] to [assignment: users/roles in Table 17]. Table 17: Management Roles of Security Attributes㩷 Security attributes General User IDs (a data item of General User Information) Administrator IDs Administrator Roles Supervisor ID Document Data ACL Operations Query, newly create, delete Query Newly create Query, change Query Query, add, delete Query, change Query, modify Document Data Default Query, ACL (a data item of modify User roles - User Administrator - General Users - Administrators - Administrators who owns the applicable Administrator IDs - Supervisor - Administrators who are assigned the applicable Administrator Roles - Supervisor - File Administrator - Document File Owner - General Users who have full control operation permission for the applicable Document Data - User Administrator - The General User who create the applicable Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83

Page 48 of 83
associated with subjects acting on the behalf of users:
[assignment: Administrators can add
their own assigned Administrator Roles to other Administrators, and can delete their
own Administrator Roles. However, if deleting the Administrator Role makes no
Administrator covers that Administrator Role, it is not allowed to delete the
Administrator Role].
6.1.5
Class FMT: Security management
FMT_MSA.1
Management of security attributes
Hierarchical to:
No other components.
Dependencies:
[FDP_ACC.1 Subset access control, or
FDP_IFC.1 Subset information flow control]
FMT_SMR.1 Security roles
FMT_SMF.1 Specification of Management Functions
FMT_MSA.1.1 The TSF shall enforce the
[assignment: MFP access control SFP]
to restrict the ability to
[selection: query, modify, delete, [assignment: newly create, change, add]]
the security
attributes
[assignment: security attributes in
Table 17
] to [assignment: users/roles in
Table 17
].
Table 17: Management Roles of Security Attributes
Security attributes
Operations
User roles
Query,
newly create,
delete
- User Administrator
General User IDs (a data
item
of
General
User
Information)
Query
- General Users
Newly create
- Administrators
Query,
change
-
Administrators
who
owns
the
applicable
Administrator IDs
Administrator IDs
Query
- Supervisor
Administrator Roles
Query,
add,
delete
- Administrators who are assigned the applicable
Administrator Roles
Supervisor ID
Query,
change
- Supervisor
Document Data ACL
Query,
modify
- File Administrator
- Document File Owner
- General Users who have full control operation
permission for the applicable Document Data
Document
Data
Default
ACL
(a
data
item
of
Query,
modify
- User Administrator
- The General User who create the applicable
Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.