Security Audit (Tsf_Fau); Table 45: Security Audit Event - Samsung X4220 Instruction Manual

Multifunction multixpress
Table of Contents

Advertisement

Samsung Multifunction MultiXpress X4220, X4250, X4300, X401, K4250, K4300, K4350, K401 Series
Management of security roles (User Group ID)
Management of TSF testing (initiation)
Management of fax forward functions
There are two types of Users in the TOE; U.NORMAL and U.ADMINISTRATOR:
U.ADMINISTRATOR has been specifically granted the authority to perform security management of
the TOE and U.NORMAL is authorized to perform User Document Data processing functions (Copy,
Scan, Fax, Print) of the TOE and to modify his/her own password.
U.USER has five roles: ADMIN, GENERAL USER, GUEST, LIMITED RESOURCE USER,
RESTRICTED INFOR USER.
Each role type has different rights predefined. U.NORMAL has no permission to access the security
management of the TOE as a general rule.
The TOE supports the role management and user profile to manage U.USER.
-Role Management: U.ADMINISTRATOR can give permissions to U.NORMAL to only use certain
features of the machine and can give different rights to different U.NORMAL by using role
management.
-User profile: The TOE shall store U.USER's information on the TOE. U.ADMINISTRATOR can
use this feature to manage the U.USER's authorization. The U.NORMAL is allowed to modify his/her
password.

7.1.4 Security Audit (TSF_FAU)

Relevant SFR: FAU_GEN.1 FAU_GEN.2, FAU_SAR.1, FAU_SAR.2, FAU_STG.1,
FAU_STG.4, FPT_STM.1
The TOE provides an internal capability to generate a audit record of the security audit event (job log,
security event log, operation log) and audit data includes the following information (type of event,
date and time of the event, subject identity, success or failure, log out, access, enabled and disabled).
U.ADMINISTRATOR only has the capability to manage this function and to read all of the audit data
(job log, security event log, operation log) from the audit records.
The TOE protects the stored audit records in the audit trail from unauthorized deletion. Additionally,
the TOE provides a capability to export audit log data from the TOE.
If the audit trail is full, the TOE overwrites the oldest stored audit records. After that, a new audit log
is generated.
Time & Date values used in security audit only can be changed by U.ADMINISTRATOR manually.
TOE use only internal time-stamps.
Auditable Events
Job completion
Copyright
Management Functions

Table 45: Security Audit Event

Relevant SFR
FDP_ACF.1(1)(2)
2014 SAMSUNG ELECTRONICS Co., Ltd., All rights reserved
Audit Level
Not specified
91
Additional
Information
Type of job

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

X4300X401K4250K4300K4350K401 series ... Show all

Table of Contents