Xerox Multi-Function Device Security Target
66
Copyright
2013 Xerox Corporation. All rights reserved.
Functional Component
Dependency (ies)
Satisfied
FDP_ACF.1(FUNC)
FDP_ACC.1
Yes, FDP_ACC.1(FUNC)
FMT_MSA.3
Yes, FMT_MSA.3 (FUNC)
FDP_IFC.1 (FILTER)
FDP_IFF.1
Yes, FDP_IFF.1 (FILTER)
FDP_IFF.1 (FILTER)
FDP_IFC.1
Yes, FDP_IFC.1 (FILTER)
FMT_MSA.3
No
3
FDP_RIP.1
None
FIA_ATD.1
None
FIA_UAU.1
FIA_UID.1
Yes
FIA_UAU.7
FIA_UAU.1
Yes
FIA_UID.1
None
FIA_USB.1
FIA_ATD.1
Yes
FMT_MSA.1(USER)
FDP_ACC.1 or
FDP_IFC.1
FDP_ACC.1 (USER)
FMT_SMF.1
Yes
FMT_SMR.1
Yes
FMT_MSA.1(FUNC)
FDP_ACC.1 or
FDP_IFC.1
FDP_ACC.1 (FUNC)
FMT_SMF.1
Yes
FMT_SMR.1
Yes
FMT_MSA.3(USER)
FMT_MSA.1
Yes, FMT_MSA.1(USER)
FMT_SMR.1
Yes
FMT_MSA.3(FUNC)
FMT_MSA.1
Yes, FMT_MSA.1(FUNC)
FMT_SMR.1
Yes
FMT_MTD.1(MGMT1)
FMT_SMF.1
Yes
FMT_SMR.1
Yes
FMT_MTD.1(MGMT2)
FMT_SMF.1
Yes
FMT_SMR.1
Yes
3
The dependency of FDP_IFF.1 (FILTER) on FMT_MSA.3 is not met because none of these functions support “a)
managing the group of roles that can specify initial values; b) managing the permissive or restrictive setting of default
values for a given access con
trol SFP; c) management of rules by which security attributes inherit specified values.”
(CC Part 2 Page 106). The TOE does not give system administrators the option of specifying default values,
permissive or otherwise. In fact, these features are configured and, with the exception of IP Filter rules, cannot be
modified by the system administrator other than to enable or disable them. It is for these reasons that the
dependency on FMT_MSA.3 is not and cannot be expected to be met.