Ricoh Aficio MP C2800 Security Target - Page 45

Table 16, Table 17

Page 45 highlights

Page 45 of 80 FDP_IFC.1 Subset information flow control] FMT_SMR.1 Security roles FMT_SMF.1 Specification of Management Functions FMT_MSA.1.1 The TSF shall enforce the [assignment: MFP access control SFP] to restrict the ability to [selection: query, modify, delete, [assignment: newly create, change, add]] the security attributes [assignment: security attributes in Table 16 to [assignment: users/roles in Table 16]. Table 16: Management roles of security attributes Security attributes General user IDs (a data item of general user information) Administrator IDs Administrator roles Supervisor ID Document data ACL Operations Query, newly create, delete Query Newly create Query, change Query Query, add, delete Query, change Query, modify Document data default ACL (a data item of general user information) Query, modify User roles - User administrator - General users - Administrators - Administrators who own the administrator IDs - Supervisor - Administrators who are assigned these administrator roles - Supervisor - File administrator - Document file owner - General users who have full control operation permissions for the relevant document data - User administrator - The general user who creates the applicable document data FMT_MSA.3 Static attribute initialisation Hierarchical to: No other components. Dependencies: FMT_MSA.1 Management of security attributes FMT_SMR.1 Security roles FMT_MSA.3.1 The TSF shall enforce the [assignment: MFP access control SFP] to provide default values [selection: [assignment: specifiedas shown inTable17] for security attributes that are used to enforce the SFP. FMT_MSA.3.2 The TSF shall allow the [assignment: no authorised identified roles] to specify alternative initial values to override the default values when an object or information is created. Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80

Page 45 of 80
Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.
FDP_IFC.1 Subset information flow control]
FMT_SMR.1 Security roles
FMT_SMF.1 Specification of Management Functions
FMT_MSA.1.1 The TSF shall
enforce the
[assignment: MFP access control SFP]
to restrict the ability to
[selection: query, modify, delete, [assignment: newly create, change, add]] the security
attributes [assignment: security attributes in
Table 16
]
to
[assignment: users/roles in
Table 16
].
Table 16: Management roles of security attributes
Security attributes
Operations
User roles
Query,
newly create,
delete
- User administrator
General user IDs (a data
item of general user
information)
Query
- General users
Newly create
- Administrators
Query,
change
- Administrators who own the administrator IDs
Administrator IDs
Query
- Supervisor
Administrator roles
Query,
add,
delete
- Administrators who are assigned these administrator
roles
Supervisor ID
Query,
change
- Supervisor
Document data ACL
Query,
modify
- File administrator
- Document file owner
- General users who have full control operation
permissions for the relevant document data
Document data default
ACL (a data item of
general user information)
Query,
modify
- User administrator
- The general user who creates the applicable
document data
FMT_MSA.3
Static attribute initialisation
Hierarchical to:
No other components.
Dependencies:
FMT_MSA.1 Management of security attributes
FMT_SMR.1 Security roles
FMT_MSA.3.1 The TSF shall enforce the
[assignment: MFP access control SFP] to provide default
values [selection: [assignment: specified as shown in
Table 17
]
for security attributes that
are used to enforce the SFP.
FMT_MSA.3.2 The TSF shall allow the
[assignment: no authorised identified roles]
to specify alternative
initial values to override the default values when an object or information is created.