Ricoh Aficio MP 3350B Security Target - Page 75

From the above, FMT_MSA.1 Management of security attributes, FMT_MTD.1 Management of TSF

Page 75 highlights

Page 75 of 83 Operations on General User Information Data Default ACL, S/MIME User Information) Query General User Information registered for Address Book (General User ID, Document Data Default ACL, S/MIME User Information) Query General User Information registered for Address Book (General User ID, S/MIME User Information) Delete General User Information registered for Address Book (General User ID, authentication information of General Users, S/MIME User Information) Delete General User Information registered for Address Book (S/MIME User Information) Authorised operators User Administrator The General User themselves General User User Administrator The General User who owns the applicable S/MIME User Information When newly creating the General User information, the newly created General User ID is set to the value for the Document Data Default ACL as the Document File Owner, and the authorised operations on Document Data of that General User are to read the Document Data and to modify the Document Data ACL. From the above, FMT_MSA.1 (Management of security attributes), FMT_MTD.1 (Management of TSF data), FMT_SMF.1 (Specification of Management Function) and FMT_SMR.1 (Security roles) are accomplished. 7.1.4.5 Management of Machine Control Data Management of Machine Control Data allows only the specific users to set Machine Control Data from specific operation interfaces. The TOE allows the specific users to use the function that sets the Machine Control Data from the specific operation interfaces. Table 33 shows the range of values that can be set, the operations, the authorised setter, and the operation interfaces allowed by the TOE, for each Machine Control Data. The TOE allows the User Administrator and General Users to query the destination information for Deliver to Folder. Table 33: List of Administrator for Machine Control Data Machine control data items Number of Attempts before Lockout Setting for Lockout Release Timer Lockout time Minimum Password Range of values An integer 1-5 (times) Active or Inactive An integer 1-9999 (minutes) An integer 8-32 Operations Query, modify Query, modify Query, modify Query, Authorised setter Machine Administrator Machine Administrator Machine Administrator User Administrator Operation interfaces Web Service Function Web Service Function Web Service Function Operation Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83

Page 75 of 83
Operations on General User Information
Authorised operators
Data Default ACL, S/MIME User Information)
Query General User Information registered for Address
Book
(General User ID, Document Data Default ACL, S/MIME
User Information)
User Administrator
The General User themselves
Query General User Information registered for Address
Book
(General User ID, S/MIME User Information)
General User
Delete General User Information registered for Address
Book
(General User ID, authentication information of General
Users, S/MIME User Information)
User Administrator
Delete General User Information registered for Address
Book
(S/MIME User Information)
The General User who owns the applicable
S/MIME User Information
When newly creating the General User information, the newly created General User ID is set to the value for
the Document Data Default ACL as the Document File Owner, and the authorised operations on Document
Data of that General User are to read the Document Data and to modify the Document Data ACL.
From the above, FMT_MSA.1 (Management of security attributes), FMT_MTD.1 (Management of TSF
data), FMT_SMF.1 (Specification of Management Function) and FMT_SMR.1 (Security roles) are
accomplished.
7.1.4.5
Management of Machine Control Data
Management of Machine Control Data allows only the specific users to set Machine Control Data from
specific operation interfaces.
The TOE allows the specific users to use the function that sets the Machine Control Data from the specific
operation interfaces. Table 33 shows the range of values that can be set, the operations, the authorised setter,
and the operation interfaces allowed by the TOE, for each Machine Control Data.
The TOE allows the User Administrator and General Users to query the destination information for Deliver
to Folder.
Table 33: List of Administrator for Machine Control Data
Machine control
data items
Range of values
Operations
Authorised setter
Operation
interfaces
Number of Attempts
before Lockout
An
integer
1-5
(times)
Query,
modify
Machine
Administrator
Web
Service
Function
Setting for Lockout
Release Timer
Active or Inactive
Query,
modify
Machine
Administrator
Web
Service
Function
Lockout time
An
integer
1-9999 (minutes)
Query,
modify
Machine
Administrator
Web
Service
Function
Minimum
Password
An integer 8-32
Query,
User Administrator
Operation
Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.