Ricoh Aficio MP C305 Security Target - Page 25

Fax Line Separation Function, Table 7 : Definition of User Data, Description, Table 8 : Definition

Page 25 highlights

Page 24 of 91 Fax Line Separation Function The Fax Line Separation Function is to restrict input information from the telephone lines so that only fax data can be received and unauthorised intrusion from the telephone lines (same as the "fax line") can be prevented. Also, this function can be used to prohibit transmissions of received faxes so that unauthorised intrusion from the telephone lines to the LAN can be prevented. 1.4.5 Protected Assets Assets to be protected by the TOE are user data, TSF data, and functions. 1.4.5.1. User Data The user data is classified into two types: document data and function data. Table 7 defines user data according to these data types. Table 7 : Definition of User Data Type Document data Function data Description Digitised documents, deleted documents, temporary documents and their fragments, which are managed by the TOE. Jobs specified by users. In this ST, a "user job" is referred to as a "job". 1.4.5.2. TSF Data The TSF data is classified into two types: protected data and confidential data. Table 8 defines TSF data according to these data types. Type Protected data Confidential data Table 8 : Definition of TSF Data Description This data must be protected from changes by unauthorised persons. No security threat will occur even this data is exposed to the public. In this ST, "protected data", listed below, is referred to as "TSF protected data". Login user name, Number of Attempts before Lockout, settings for Lockout Release Timer, lockout time, date settings (year/month/day), time settings, Minimum Character No., Password Complexity Setting, Operation Panel auto logout time, WIM auto logout time, S/MIME user information, destination folder, Stored Reception File User, document user list, available function list, user authentication method, IPSec setting information, @Remote setting information, and Device Certificate. This data must be protected from changes by unauthorised persons and reading by users without viewing permissions. In this ST, "confidential data", listed below, is referred to as "TSF confidential data". Login password, audit log, and HDD cryptographic key. Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92

Page 24 of
91
Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.
Fax Line Separation Function
The Fax Line Separation Function is to restrict input information from the telephone lines so that only fax
data can be received and unauthorised intrusion from the telephone lines (same as the "fax line") can be
prevented. Also, this function can be used to prohibit transmissions of received faxes so that unauthorised
intrusion from the telephone lines to the LAN can be prevented.
1.4.5
Protected Assets
Assets to be protected by the TOE are user data, TSF data, and functions.
1.4.5.1.
User Data
The user data is classified into two types: document data and function data. Table 7 defines user data
according to these data types.
Table 7 : Definition of User Data
Type
Description
Document data
Digitised documents, deleted documents, temporary documents and their
fragments, which are managed by the TOE.
Function data
Jobs specified by users. In this ST, a "user job" is referred to as a "job".
1.4.5.2.
TSF Data
The TSF data is classified into two types: protected data and confidential data. Table 8 defines TSF data
according to these data types.
Table 8 : Definition of TSF Data
Type
Description
Protected data
This data must be protected from changes by unauthorised persons. No security
threat will occur even this data is exposed to the public. In this ST, "protected
data", listed below, is referred to as "TSF protected data".
Login user name, Number of Attempts before Lockout, settings for Lockout
Release Timer, lockout time, date settings (year/month/day), time settings,
Minimum Character No., Password Complexity Setting, Operation Panel auto
logout time, WIM auto logout time, S/MIME user information, destination folder,
Stored Reception File User, document user list, available function list, user
authentication method, IPSec setting information, @Remote setting information,
and Device Certificate.
Confidential data
This data must be protected from changes by unauthorised persons and reading by
users without viewing permissions. In this ST, "confidential data", listed below, is
referred to as "TSF confidential data".
Login password, audit log, and HDD cryptographic key.