Ricoh Aficio MP 8001 sec - Page 74

Management of Supervisor or Information, 1.4.4, Management of General User Information

Page 74 highlights

Operations on administrator information Delete administrator roles Authorised users Page 73 of 82 Administrators already assigned that administrator role (However, no administrator roles can be deleted unless these roles are assigned to another administrator.) If the logged-in user is an administrator or supervisor, the TOE allows that user to perform the operations shown in Table 31, respectively. By the above, FIA_USB.1 (User-subject binding), FMT_MSA.1 (Management of security attributes), FMT_MTD.1 (Management of TSF data), FMT_SMF.1 (Specification of management functions) and FMT_SMR.1 (Security roles) are satisfied. 7.1.4.3 Management of Supervisor or Information Management of supervisor information allows only a supervisor to query and change supervisor ID, and to change supervisor authentication information from the Operation Panel or Web Service Function. If the logged-in user from the Operation Panel or a client computer is a supervisor, the TOE allows that user to query and change supervisor ID and to change supervisor authentication information. By the above, FMT_MSA.1 (Management of security attributes), FMT_MTD.1 (Management of TSF data), FMT_SMF.1 (Specification of management functions), and FMT_SMR.1 (Security roles) are satisfied. 7.1.4.4 Management of General User Information Management of general user information allows only specified users to perform all or some of the operations involved in creating, changing, and deleting general user information from the Operation Panel or Web Service Function. General user information includes general user IDs, general user authentication information, document data default ACL, and S/MIME user information. If the logged-in user from the Operation Panel and Web Service Function is a user administrator or general user, the TOE allows that user to perform the operations shown in Table 32. Table 32: Authorised operations on general user information Operations on general user information Creation of new general user information to Address Book (general user ID, general user authentication information, and S/MIME user information) Edit general user information registered to Address Book (authentication information of general users, document data default ACL, S/MIME user information) Query general user information registered to Address Book (general user ID, document data default ACL, S/MIME user information) Authorised user User administrators User administrators General users themselves User administrators General users themselves Copyright (c) 2010 RICOH COMPANY, LTD. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83

Page 73 of 82
Copyright (c) 2010 RICOH COMPANY, LTD. All Rights Reserved.
Operations on administrator
information
Authorised users
Delete administrator roles
Administrators already assigned that administrator role
(However, no administrator roles can be deleted unless these roles
are assigned to another administrator.)
If the logged-in user is an administrator or supervisor, the TOE allows that user to perform the operations
shown in Table 31, respectively.
By the above, FIA_USB.1 (User-subject binding), FMT_MSA.1 (Management of security attributes),
FMT_MTD.1 (Management of TSF data), FMT_SMF.1 (Specification of management functions) and
FMT_SMR.1 (Security roles) are satisfied.
7.1.4.3
Management of Supervisor or Information
Management of supervisor information allows only a supervisor to query and change supervisor ID, and to
change supervisor authentication information from the Operation Panel or Web Service Function.
If the logged-in user from the Operation Panel or a client computer is a supervisor, the TOE allows that user
to query and change supervisor ID and to change supervisor authentication information.
By the above, FMT_MSA.1 (Management of security attributes), FMT_MTD.1 (Management of TSF data),
FMT_SMF.1 (Specification of management functions), and FMT_SMR.1 (Security roles) are satisfied.
7.1.4.4
Management of General User Information
Management of general user information allows only specified users to perform all or some of the
operations involved in creating, changing, and deleting general user information from the Operation Panel
or Web Service Function. General user information includes general user IDs, general user authentication
information, document data default ACL, and S/MIME user information.
If the logged-in user from the Operation Panel and Web Service Function is a user administrator or general
user, the TOE allows that user to perform the operations shown in Table 32.
Table 32: Authorised operations on general user information
Operations on general user information
Authorised user
Creation of new general user information to Address Book
(general user ID, general user authentication information,
and S/MIME user information)
User administrators
Edit general user information registered to Address Book
(authentication information of general users, document
data default ACL, S/MIME user information)
User administrators
General users themselves
Query general user information registered to Address
Book
(general user ID, document data default ACL, S/MIME
user information)
User administrators
General users themselves