
Fuji Xerox ApeosPort-II C4300(AP)Series Security Kit for Asia Pacific Security Target V1.01
- 41 -
Print data is included in the used document data that is stored on the hard disk drive
when using printer function. This print data is sometimes described in text format and is
relatively easy to be parsed. Therefore, TOE makes the recovery of used document
data stored on the hard disk drive impossible by encrypting the document data stored
on the hard disk drive by satisfying O.DECIPHER and then overwriting and erasing the
data by satisfying
O.RESIDUAL.
-
OE.FUNCON
By satisfying
OE.FUNCON, key operator operates TOE security functions (“HDD
overwriting function for residual data” and “HDD data encryption function”) in the
condition where these functions are enabled and completely performed.
T.CONFDATA
To counter this threat, the person who changes TOE setting data needs to be limited to
the authenticated key-operator.
By satisfying the following objective,
T.CONFDATA can be countered:
- O.MANAGE
By satisfying
O.MANAGE, only the authenticated key-operator becomes able to change
TOE setting data.
A.SECMODE By satisfying the following objective, A.SECMODE can be realized:
-
OE.AUTH
By satisfying
OE.AUTH, key operator operates TOE by:
- managing “key-operator’s password” so that it is prevented from being guessed or
disclosed.
- setting “key-operator’s password” to 7 to 12 alphanumeric characters.
- setting “access denial due to failure in authentication of key-operator’s ID” to 5-time in
the condition where “customer-engineer operation restriction function” and ”setting for
using password” are set to function.
A.ADMIN By satisfying the following objective, A.ADMIN can be realized:
-
OE.ADMIN
By satisfying
OE.ADMIN, organization person in charge selects suitable member for
key operator and provides management and education.
A.NET
In this assumption, the conditions such as the following are assumed:
- Interceptions on the internal network that MFP is connected to are not made.
- Attacks by attackers from the external network are not made.
By satisfying the following objective,
A.NET can be realized:
-
OE.NET
In
OE.NET, the devices are installed to realize the environment where interceptions on
the internal network are not made. In
OE.NET, the proper environment-settings to avoid
interception are assumed to be made by taking measures such as encryption of the
communication between client PC and MFP. And in
OE.NET, the devices to shut down
the access from the external network to MFP are specified to be properly installed so
that the external access is shut down.
Kommentare zu diesen Handbüchern