Page 54 of 93
Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.
FDP_ACF.1.1(a) The TSF shall enforce the [assignment: document access control SFP] to objects based on the
following: [assignment: subjects or objects, and their corresponding security attributes
shown in Table 17].
Table 17 : Subjects, Objects and Security Attributes (a)
Category Subjects or Objects Security Attributes
Subject Normal user process - Login user name of normal user
- User role
Subject MFP administrator process - User role
Subject Supervisor process - User role
Subject RC Gate process - User role
Object Document data - Document data attribute
- Document user list
Object User job - Login user name of normal user
FDP_ACF.1.2(a) The TSF shall enforce the following rules to determine if an operation among controlled
subjects and controlled objects is allowed: [assignment: rules to control operations among
subjects and objects shown in Table 18].
Table 18 : Rules to Control Operations on Document Data and User Jobs (a)
Objects Document Data
Attributes
Operations Subjects Rules to control Operations
Document
data
+PRT Delete Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+PRT Read Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+SCN Delete Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+SCN Read Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+FAXOUT Delete Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.
Document
data
+FAXOUT Read Normal user
process
Not allowed. However, it is allowed for
normal user process that created the
document data.