Table 19: Rules On User Jobs (A); Table 20: Rules That Explicitly Authorise Access (A); Table 21: Subjects, Objects And Security Attributes (B) - Ricoh Aficio MP 7001 SP Manual

With dataoverwritesecurity unit type h security target
Hide thumbs Also See for Aficio MP 7001 SP:
Table of Contents

Advertisement

Subject
Operation on Object
Normal
user
Deletion of user job
process
FDP_ACF.1.3(a) The TSF shall explicitly authorise access of subjects to objects based on the following
additional rules: [assignment: rules that explicitly authorise access of subjects to objects
shown in Table 20].
Subject
Operations on Object
MFP
Deletion of user document
administrator
process
MFP
Deletion of user job
administrator
process
FDP_ACF.1.4(a) The TSF shall explicitly deny access of subjects to objects based on the following additional
rules: [assignment: rules that deny the operations on the user documents and user jobs
when logged in with login user name of supervisor].
FDP_ACF.1(b) Security attribute based access control
Hierarchical to:
No other components.
Dependencies:
FDP_ACC.1 Subset access control
FMT_MSA.3 Static attribute initialisation
FDP_ACF.1.1(b) The TSF shall enforce the [assignment: TOE function access control SFP] to objects based
on the following: [assignment: subjects or objects, and their corresponding security
attributes shown in Table 21].
Category
Subject
Normal user process
Object
MFP application
FDP_ACF.1.2(b) The TSF shall enforce the following rules to determine if an operation among controlled
subjects and controlled objects is allowed: [assignment: operations on objects by subjects
and rules governing access to operations shown in Table 22].
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

Table 19: Rules on User Jobs (a)

Table 20: Rules That Explicitly Authorise Access (a)

Table 21: Subjects, Objects and Security Attributes (b)

Subject or Object
Rule Governing Access
When the login user name of normal user associated with the
normal user process matches the login user name of normal
user associated with the user job, deletion of user job is
allowed for that normal user process.
Rules That Explicitly Authorise Access
Allows the MFP administrator process to delete all of the
stored user documents.
Allows the MFP administrator process to delete all user jobs.
Security Attributes
Login user name of normal user, available function
list
Function type
Page 51 of 87

Advertisement

Table of Contents
loading

Table of Contents