Xerox Multi-Function Device Security Target
46
Copyright
2013 Xerox Corporation. All rights reserved.
6.3.4.2. FDP_ACC.1 (FUNC) Subset access control
Hierarchical to:
No other components.
Dependencies:
FDP_ACF.1 Security attribute based access control
FDP_ACC.1.1 (FUNC)
The TSF shall enforce the [TOE Function Access
Control SFP] on [users as subjects, TOE functions as
objects, and the right to use the functions as operations].
Application Note:
This SFR is FDP_ACC.1 (b) from The IEEE Std. 2600.2
PP.
6.3.4.3. FDP_ACF.1 (USER) Security attribute based access
control
Hierarchical to:
No other components.
Dependencies:
FDP_ACC.1 Subset access control
FMT_MSA.3 Static attribute initialisation
FDP_ACF.1.1 (USER)
The TSF shall enforce the [User Access Control
SFP in Table 21] to objects based on the following: [the
list of users as subjects and objects controlled under the
User Access Control SFP in Table 21, and for each, the
indicated security attributes in Table 21].
FDP_ACF.1.2 (USER)
The TSF shall enforce the following rules to
determine if an operation among controlled subjects and
controlled objects is allowed: [rules specified in the User
Access Control SFP in Table 21 governing access among
controlled users as subjects and controlled objects using
controlled operations on controlled objects].
FDP_ACF.1.3 (USER)
The TSF shall explicitly authorise access of
subjects to objects based on the following additional
rules: [none].
FDP_ACF.1.4 (USER)
The TSF shall explicitly deny access of subjects to
objects based on the [none].
Application Note:
This SFR covers FDP_ACF.1 (a) and FDP_ACF.1 from
all claimed packages (PRT, SCN, CPY, FAX, DSR) in the IEEE Std. 2600.2
PP.
6.3.4.4. FDP_ACF.1 (FUNC) Security attribute based access
control
Hierarchical to:
No other components.
Dependencies:
FDP_ACC.1 Subset access control
FMT_MSA.3 Static attribute initialisation