![Samsung K401 series Instruction Manual Download Page 40](http://html.mh-extra.com/html/samsung/k401-series/k401-series_instruction-manual_352208040.webp)
Samsung Multifunction MultiXpress X4220, X4250, X4300, X401, K4250, K4300, K4350, K401 Series
40
Copyright
2014 SAMSUNG ELECTRONICS Co., Ltd., All rights reserved
Threats, Policies, and
Assumptions
Summary
Objectives and Rationale
P.SOFTWARE.VERIF
ICATION
Procedures will exist to self-
verify executable code in the TSF
O.SOFTWARE.VERIFIED provides procedures
to self-verify executable code in the TSF.
P.AUDIT.LOGGING
An audit trail of TOE use and
security-relevant events will be
created, maintained, protected,
and reviewed
O.AUDIT.LOGGED creates and maintains a log
of TOE use and security-relevant events, and
prevents unauthorized disclosure or alteration
O.AUDIT_STORAGE.PROTEDTED protects
audit records from unauthorized access, deletion,
and modification.
O.AUDIT_ACCESS.AUTHORIZED allows the
access of audit records only by authorized
persons,
OE.AUDIT_STORAGE.PROTECTED protects
exported audit records from unauthorized access,
deletion and modification,
OE.AUDIT_ACCESS.AUTHORIZED
establishes responsibility of the TOE Owner to
provide appropriate access to exported audit
records.
OE.AUDIT.REVIEWED establishes
responsibility of the TOE Owner to ensure that
audit logs are appropriately reviewed.
P.INTERFACAE.MA
NAGEMENT
Operation of external interfaces
will be controlled by the TOE and
its IT environment
O.INTERFACE.MANAGED manages the
operation of external interfaces in accordance
with security policies.
OE.INTERFACE.MANAGED establishes a
protected environment for TOE external
interfaces
A.ACCESS.MANAGE
D
The TOE environment provides
protection
from
unmanaged
access to the physical components
and data interfaces of the TOE
OE.PHYSICAL.MANAGED establishes a
protected physical environment for the TOE.
A.ADMIN.TRAININ
G
Administrators are aware of and
trained to follow security policies
and procedures
OE.ADMIN.TRAINED establishes
responsibility of the TOE Owner to provide
appropriate Administrator training.
A.ADMIN.TRUST
Administrators do not use their
privileged
access
rights
for
malicious purposes
OE.ADMIN.TRUST establishes responsibility of
the TOE Owner to have a trusted relationship
with Administrators.
A.USER.TRAINING
TOE Users are aware of and
trained to follow security policies
and procedures
OE.USER.TRAINED establishes responsibility
of the TOE Owner to provide appropriate user
training.