Ricoh Aficio MP 5002 Security Target - Page 71

O.DOC.NO_DIS Protection of document disclosure

Page 71 highlights

Page 70 of 93 O.DOC.NO_DIS O.DOC.NO_ALT O.FUNC.NO_ALT O.PROT.NO_ALT O.CONF.NO_DIS O.CONF.NO_ALT O.USER.AUTHORIZED O.INTERFACE.MANAGED O.SOFTWARE.VERIFIED O.AUDIT.LOGGED O.STORAGE.ENCRYPTED O.RCGATE.COMM.PROTECT FIA_USB.1 X FPT_FDI_EXP.1 X FMT_MSA.1(a) X X X FMT_MSA.1(b) X FMT_MSA.3(a) X X X FMT_MSA.3(b) X FMT_MTD.1 X X X X FMT_SMF.1 X X X X FMT_SMR.1 X X X X FPT_STM.1 X FPT_TST.1 X FTA_SSL.3 X X FTP_ITC.1 X X X X X X X 6.3.2 Justification of Traceability This section describes below how the TOE security objectives are fulfilled by the TOE security functional requirements corresponding to the TOE security objectives. O.DOC.NO_DIS Protection of document disclosure O.DOC.NO_DIS is the security objective to prevent the documents from unauthorised disclosure by persons without a login user name, or by persons with a login user name but without an access permission to the document. To fulfil this security objective, it is required to implement the following countermeasures. (1) Specify and implement the access control to the document data. FDP_ACC.1(a) and FDP_ACF.1(a) only allow the following persons to view document data according to the document data attributes: the normal user who generated the document data or the normal user who is registered on the document user list of the document data. The MFP administrator, supervisor and RC Gate are not allowed to view document data. Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94

Page 70 of
93
Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.
O.DOC.NO_DIS
O.DOC.NO_ALT
O.FUNC.NO_ALT
O.PROT.NO_ALT
O.CONF.NO_DIS
O.CONF.NO_ALT
O.USER.AUTHORIZED
O.INTERFACE.MANAGED
O.SOFTWARE.VERIFIED
O.AUDIT.LOGGED
O.STORAGE.ENCRYPTED
O.RCGATE.COMM.PROTECT
FIA_USB.1
X
FPT_FDI_EXP.1
X
FMT_MSA.1(a)
X
X
X
FMT_MSA.1(b)
X
FMT_MSA.3(a)
X
X
X
FMT_MSA.3(b)
X
FMT_MTD.1
X
X
X
X
FMT_SMF.1
X
X
X
X
FMT_SMR.1
X
X
X
X
FPT_STM.1
X
FPT_TST.1
X
FTA_SSL.3
X
X
FTP_ITC.1
X
X
X
X
X
X
X
6.3.2
Justification of Traceability
This section describes below how the TOE security objectives are fulfilled by the TOE security functional
requirements corresponding to the TOE security objectives.
O.DOC.NO_DIS Protection of document disclosure
O.DOC.NO_DIS is the security objective to prevent the documents from unauthorised disclosure by persons
without a login user name, or by persons with a login user name but without an access permission to the
document. To fulfil this security objective, it is required to implement the following countermeasures.
(1)
Specify and implement the access control to the document data.
FDP_ACC.1(a) and FDP_ACF.1(a) only allow the following persons to view document data according
to the document data attributes: the normal user who generated the document data or the normal user
who is registered on the document user list of the document data. The MFP administrator, supervisor
and RC Gate are not allowed to view document data.