Xerox Multi-Function Device Security Target
47
Copyright
2013 Xerox Corporation. All rights reserved.
FDP_ACF.1.1 (FUNC)
The TSF shall enforce the [TOE Function Access
Control SFP] to objects based on the following: [Users
and their role based permissions to perform any or all of
the following functions: print, scan, copy, fax, document
storage and retrieval, access to shared-medium
interface].
FDP_ACF.1.2 (FUNC)
The TSF shall enforce the following rules to
determine if an operation among controlled subjects and
controlled objects is allowed: [users assigned to a role
that is explicitly authorized by U.ADMINISTATOR
(System Administrator) to use a function is allowed to
access the function].
FDP_ACF.1.3 (FUNC)
The TSF shall explicitly authorise access of
subjects to objects based on the following additional
rules: [none].
FDP_ACF.1.4 (FUNC)
The TSF shall explicitly deny access of subjects to
objects based on the [none].
Application Note:
This SFR is FDP_ACF.1 (b) from The IEEE Std. 2600.2
PP.
6.3.4.5. FDP_IFC.1 (FILTER) Subset information flow control
Hierarchical to:
No other components.
Dependencies:
FDP_IFF.1 Simple security attributes
FDP_IFC.1.1 (FILTER)
The TSF shall enforce the [IPFilter SFP] on [
-
Subjects: External entities that send traffic to the
TOE;
-
Information:
All
IP-based
traffic
to/from
that
source/destination;
-
Operations: send or receive network traffic].
6.3.4.6. FDP_IFF.1 (FILTER) Simple security attributes
Hierarchical to:
No other components.
Dependencies:
FDP_IFC.1 Subset information flow control
FMT_MSA.3 Static attribute initialization.
FDP_IFF.1.1 (FILTER)
The TSF shall enforce the [IPFilter SFP] based on
the following types of subject and information security
attributes: [
-
Subjects: External entities that send traffic to the TOE
o
IP address,