Page 63 of 93
Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.
Dependencies: FMT_MSA.1 Management of security attributes
FMT_SMR.1 Security roles
FMT_MSA.3.1(a) The TSF shall enforce the [assignment: document access control SFP] to provide [selection:
restrictive] default values for security attributes that are used to enforce the SFP.
FMT_MSA.3.2(a) The TSF shall allow the [assignment: authorised identified roles shown in Table 28] to
specify alternative initial values to override the default values when an object or information is
created.
Table 28 : Authorised Identified Roles Allowed to Override Default Values
Objects Security
Attributes
Authorised Identified Roles
Document data Document data
attribute
No authorised identified roles
Document data
[when document data
attribute is (+DSR)]
Document user list MFP administrator,
Normal user who stored the applicable document
data
Document data
[when document data
attributes are (+PRT),
(+SCN), (+CPY),
(+FAXIN), and
(+FAXOUT)]
Document user list No authorised identified roles
User job Login user name
of normal user
No authorised identified roles
FMT_MSA.3(b) Static attribute initialisation
Hierarchical to: No other components.
Dependencies: FMT_MSA.1 Management of security attributes
FMT_SMR.1 Security roles
FMT_MSA.3.1(b)The TSF shall enforce the [assignment: TOE function access control SFP] to provide
[selection: restrictive] default values for security attributes that are used to enforce the SFP.
FMT_MSA.3.2(b) The TSF shall allow the [assignment: no authorised identified roles] to specify alternative
initial values to override the default values when an object or information is created.
FMT_MTD.1 Management of TSF data
Hierarchical to: No other components.
Dependencies: FMT_SMR.1 Security roles
FMT_SMF.1 Specification of Management Functions
FMT_MTD.1.1 The TSF shall restrict the ability to [selection: query, modify, delete, [assignment: newly
create]] the [assignment: list of TSF data in Table 29] to [assignment: the user roles in
Table 29].