Ricoh Aficio MP C305 Security Target - Page 84

Document Access Control Function

Page 84 highlights

Page 83 of 91 7.3 Document Access Control Function The Document Access Control Function is to allow authorised TOE users to operate document data and user jobs in accordance with the provided user role privilege or user privilege. FDP_ACC.1(a) and FDP_ACF.1(a) The TOE controls user operations for document data and user jobs in accordance with (1) access control rule on document data and (2) access control rule on user jobs. (1) Access control rule on document data The TOE provides users with the interface for stored documents to be printed, downloaded to the client computers, sent by fax, sent by e-mail as attachments, sent to folders, and deleted. The interface enables users to delete all the stored documents. Users authorised to operate stored documents are MFP administrator and normal users. The supervisor and RC Gate are not allowed to operate stored documents. When the MFP administrator or a normal user logs on to the TOE from the Operation Panel or to WIM from the client computer, the TOE displays a list of the stored documents whose operations are authorised and the menu for the authorised operations (printing, downloading to the client computers, sending by fax, sending by e-mail as attachments, sending to folders, deleting, and deleting all files). When the MFP administrator logs on to the TOE from the Operation Panel or to WIM from the client computer, the TOE displays a list of all the stored documents and the operation menu for deletion and deletion of all files. The MFP administrator can select and delete a document from the list of the stored documents or all documents. When a normal user logs on to the TOE from the Operation Panel or to WIM from the client computer, the TOE displays a list of the stored documents that register the login user names of the normal users who logged in to the document user list, and an operation menu. They will be displayed according to the rules shown in Table 36. The privileges that allow users to edit the document user list are shown in "7.8 Security Management Function". Also, the TOE allows only the user job owner to view and delete the document data handled as a user job while Copy Function, Printer Function, Scanner Function, Fax Function, or Document Server Function is being used. While no interface to change job owners is provided, an interface to cancel user jobs is provided. If a user job is cancelled, any document the cancelled job operates will be deleted. Table 36 : Stored Documents Access Control Rules for Normal Users I/F to be Used Operation Panel Operation Panel Available Functions for Users Document Server Function Document Server Function Types of Stored Documents displayed in the List Document Server documents Fax transmission documents Operations displayed on the Menu Print Delete Print Delete Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92

Page 83 of
91
Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.
7.3
Document Access Control Function
The Document Access Control Function is to allow authorised TOE users to operate document data and user
jobs in accordance with the provided user role privilege or user privilege.
FDP_ACC.1(a) and FDP_ACF.1(a)
The TOE controls user operations for document data and user jobs in accordance with (1) access control rule
on document data and (2) access control rule on user jobs.
(1)
Access control rule on document data
The TOE provides users with the interface for stored documents to be printed, downloaded to the client
computers, sent by fax, sent by e-mail as attachments, sent to folders, and deleted. The interface enables
users to delete all the stored documents.
Users authorised to operate stored documents are MFP administrator and normal users. The supervisor
and RC Gate are not allowed to operate stored documents.
When the MFP administrator or a normal user logs on to the TOE from the Operation Panel or to WIM
from the client computer, the TOE displays a list of the stored documents whose operations are
authorised and the menu for the authorised operations (printing, downloading to the client computers,
sending by fax, sending by e-mail as attachments, sending to folders, deleting, and deleting all files).
When the MFP administrator logs on to the TOE from the Operation Panel or to WIM from the client
computer, the TOE displays a list of all the stored documents and the operation menu for deletion and
deletion of all files. The MFP administrator can select and delete a document from the list of the stored
documents or all documents.
When a normal user logs on to the TOE from the Operation Panel or to WIM from the client computer,
the TOE displays a list of the stored documents that register the login user names of the normal users
who logged in to the document user list, and an operation menu. They will be displayed according to the
rules shown in Table 36. The privileges that allow users to edit the document user list are shown in "7.8
Security Management Function".
Also, the TOE allows only the user job owner to view and delete the document data handled as a user
job while Copy Function, Printer Function, Scanner Function, Fax Function, or Document Server
Function is being used.
While no interface to change job owners is provided, an interface to cancel user jobs is provided. If a
user job is cancelled, any document the cancelled job operates will be deleted.
Table 36 : Stored Documents Access Control Rules for Normal Users
I/F to be Used
Available Functions
for Users
Types of Stored Documents
displayed in the List
Operations
displayed on the Menu
Operation
Panel
Document Server
Function
Document Server documents
Print
Delete
Operation
Panel
Document Server
Function
Fax transmission documents
Print
Delete