Xerox Multi-Function Device Security Target
26
Copyright
2013 Xerox Corporation. All rights reserved.
Objective
Definition
O.AUDIT_STORAGE.PRO
TECTED
The TOE shall ensure that internal audit records are
protected from unauthorized access, deletion and
modifications.
4.2.
Security Objectives for the
Operational Environment
This section describes the security objectives that must be fulfilled by IT
methods in the IT environment of the TOE.
Table 17: Security objectives for the IT environment
Objective
Definition
OE.AUDIT_STORAGE.PROTECTED If audit records are exported from the TOE to
another trusted IT product, the TOE Owner shall
ensure that those records are protected from
unauthorized access, deletion and modifications.
OE.AUDIT_ACCESS.AUTHORIZED
If audit records generated by the TOE are
exported from the TOE to another trusted IT
product, the TOE Owner shall ensure that those
records can be accessed in order to detect
potential security violations, and only by
authorized persons
OE.INTERFACE.MANAGED
The IT environment shall provide protection from
unmanaged access to TOE external interfaces.
OE.USER.AUTHENTICATED
The IT environment shall provide support for user
identification and authentication and protect the
user credentials in transit when TOE operates in
remote identification and authentication mode.