Ricoh Aficio MP 3351 Security Target - Page 86

FMT_SMR.1 Security roles

Page 86 highlights

Page 85 of 87 - Query of S/MIME user information by normal user - New creation, modification, query and deletion of destination folder for folder transmission by MFP administrator - Query of destination folder for folder transmission by normal user - Query and modification of users for stored and received documents by MFP administrator FMT_SMR.1 (Security roles) The TOE binds the successfully identified and authenticated users with the user role processes associated with them and maintains this binding. When registering users in the TOE, it assigns the user roles of normal user, supervisor or MFP administrator to the users. The TOE allows only specified users to operate the login user name and password, and maintains the security roles. MFP administrator is allowed the following operations: - New creation, modification and deletion of the login user name of normal user - New creation of login user name of MFP administrator - New creation of login password of normal user - New creation of login password of MFP administrator - Management of users for stored and received documents - Management of HDD cryptographic key - New creation, modification and deletion of S/MIME user information - New creation, modification and deletion of destination folder for folder transmission An MFP administrator is allowed the following operations: - Modification of that MFP administrator's login user name A normal user and MFP administrator are allowed the following operations: - Query of login user name of that normal user - Modification of login password of that normal user - Query of that normal user's S/MIME user information - Query of that normal user's destination folder for folder transmission An MFP administrator and supervisor are allowed the following operations: - Query of login user name of that MFP administrator - Modification of login password of that MFP administrator A supervisor is allowed the following operations: - Query and modification of login user name of supervisor - Modification of login password of supervisor Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88

Page 85 of
87
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
-
Query of S/MIME user information by normal user
-
New creation, modification, query and deletion of destination folder for folder
transmission by MFP administrator
-
Query of destination folder for folder transmission by normal user
-
Query and modification of users for stored and received documents by MFP
administrator
FMT_SMR.1 (Security roles)
The TOE binds the successfully identified and authenticated users with the user role processes associated
with them and maintains this binding. When registering users in the TOE, it assigns the user roles of normal
user, supervisor or MFP administrator to the users.
The TOE allows only specified users to operate the login user name and password, and maintains the
security roles.
MFP administrator is allowed the following operations:
-
New creation, modification and deletion of the login user name of normal user
-
New creation of login user name of MFP administrator
-
New creation of login password of normal user
-
New creation of login password of MFP administrator
-
Management of users for stored and received documents
-
Management of HDD cryptographic key
-
New creation, modification and deletion of S/MIME user information
-
New creation, modification and deletion of destination folder for folder transmission
An MFP administrator is allowed the following operations:
-
Modification of that MFP administrator's login user name
A normal user and MFP administrator are allowed the following operations:
-
Query of login user name of that normal user
-
Modification of login password of that normal user
-
Query of that normal user's S/MIME user information
-
Query of that normal user's destination folder for folder transmission
An MFP administrator and supervisor are allowed the following operations:
-
Query of login user name of that MFP administrator
-
Modification of login password of that MFP administrator
A supervisor is allowed the following operations:
-
Query and modification of login user name of supervisor
-
Modification of login password of supervisor