Xerox Multi-Function Device Security Target
30
Copyright
2013 Xerox Corporation. All rights reserved.
Threats. Policies, and
Assumptions
Summary
Objectives and rationale
OE.USER.AUTHORIZED
establishes responsibility of the
TOE Owner to appropriately grant
authorization
OE.USER.AUTHENTICATED
establishes alternative (remote)
means for user identification and
authentication as the basis for
authorization
T.CONF.DIS
TSF Confidential Data
may be disclosed to
unauthorized persons
O.CONF.NO_DIS protects D.CONF
from unauthorized disclosure
O.USER.AUTHORIZED
establishes user identification and
authentication as the basis for
authorization
OE.USER.AUTHORIZED
establishes responsibility of the
TOE Owner to appropriately grant
authorization
OE.USER.AUTHENTICATED
establishes alternative (remote)
means for user identification and
authentication as the basis for
authorization
T.CONF.ALT
TSF Confidential Data
may be altered by
unauthorized persons
O.CONF.NO_ALT protects
D.CONF from unauthorized
alteration
O.USER.AUTHORIZED
establishes user identification and
authentication as the basis for
authorization
OE.USER.AUTHORIZED
establishes responsibility of the
TOE Owner to appropriately grant
authorization
OE.USER.AUTHENTICATED
establishes alternative (remote)
means for user identification and
authentication as the basis for
authorization
P.USER.AUTHORIZATION
Users will be
authorized to use the
TOE
O.USER.AUTHORIZED
establishes user identification and
authentication as the basis for
authorization to use the TOE