19.06.2014 Views

Xerox WorkCentre 5632/5638/5645/5655 - Common Criteria

Xerox WorkCentre 5632/5638/5645/5655 - Common Criteria

Xerox WorkCentre 5632/5638/5645/5655 - Common Criteria

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Xerox</strong> <strong>WorkCentre</strong> <strong>5632</strong>/<strong>5638</strong>/<strong>5645</strong>/<strong>5655</strong>/5665/5675/5687<br />

Multifunction Systems Security Target<br />

TE.COMM_SEC<br />

operational changes to the TOE that would remove it<br />

from the evaluated configuration or allow them to<br />

access job data. Additionally O.MANAGE counters<br />

T.USER by requiring authorized users to be identified<br />

and authenticated before providing access to use<br />

installed network options of the TOE. O.MANAGE<br />

also protects against brute-force attacks against the<br />

password at the local user interface.<br />

OE.NETWORK ensures that brute-force attacks<br />

against the password are also not possible at the web<br />

interface.<br />

OE.PROTECT_COM helps mitigate the threat<br />

T.COMM_SEC and helps meet OSPs<br />

P.COMMS_SEC and P.SSL_ENABLED by ensuring<br />

that fully-compliant (A.EXT_RFC_COMPLIANT)<br />

trusted channel between the TOE and another remote<br />

trusted IT product exists to protect management data<br />

from disclosure or modification by an attacker<br />

attempting to intercept communications between the<br />

TOE and the remote trusted IT product.<br />

4.3.3. Implementation of Organizational Security Policies<br />

P.COMMS_SEC<br />

O.PROTECT_COM helps meet P.COMMS_SEC by<br />

ensuring that a fully-compliant trusted channel<br />

between the TOE and another remote trusted IT<br />

product exists to protect management data from<br />

disclosure or modification by an attacker attempting<br />

to intercept communications between the TOE and<br />

the remote trusted IT product.<br />

P.HIPAA_OPT<br />

P.SSL_ENABLED<br />

OE.ADMIN helps meet P.COMMS_SEC by ensuring<br />

that local site security policies have been complied<br />

with by a competent administrator.<br />

O.AUDITS helps satisfy OSP P.HIPA_OPT by<br />

ensuring that log entries are provided by the TOE for<br />

periodic review by a competent administrator<br />

(OE.ADMIN), to ensure that safeguards for<br />

information mandated by applicable laws and<br />

regulations remain in place, and that audit logs<br />

available to mitigate the risk of improper disclosure<br />

and to support application of sanctions following<br />

improper disclosure.<br />

O.PROTECT_COM helps meet P.SSL_ENABLED by<br />

ensuring that a fully-compliant trusted channel<br />

between the TOE and another remote trusted IT<br />

33<br />

Copyright 2009 <strong>Xerox</strong> Corporation, All rights reserved

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!