HP Inc.
HP LaserJet Enterprise MFP M527 Series,
Color LaserJet Enterprise MFP M577 Series, and
PageWide Enterprise Color MFP 586 Series
Firmware with Jetdirect Inside Security Target
Version: 2.0 Copyright © 2008-2016 by atsec information security corporation and HP Inc. Page 24 of 98
Last update: 2016-06-07 or its wholly owned subsidiaries
The “Save to HTTP” function is disallowed and must not be configured to function with an HTTP
server
Display Names for the Local Device Sign In method users and user names for the LDAP and
Windows Sign In method users must only contain the characters defined in
P.USERNAME.CHARACTER_SET
Remote Control-Panel use is disallowed per P.REMOTE_PANEL.DISALLOWED
1.5.4 Security policy model
This section describes the security policy model for the TOE. Much of the terminology in this section
comes from [PP2600.2] and is duplicated here so that readers won't have to read [PP2600.2] to
understand the terminology used in the rest of this Security Target document.
Subjects/Users 1.5.4.1
Users are entities that are external to the TOE and which interact with the TOE. TOE users are defined in
Table 4.
Any authorized User. Authorized Users are U.ADMINISTRATOR and U.NORMAL.
A User who is authorized to perform User Document Data
processing functions of the TOE.
A User who has been specifically granted the authority to
manage some portion or all of the TOE and whose actions may
affect the TOE security policy (TSP). A password must be set
for all U.ADMINISTRATOR accounts in the evaluated
configuration.
Table 4: Users
For the purpose of clarity in this Security Target, the following distinctions are made:
Control Panel users – U.NORMAL and U.ADMINISTRATOR users who physically access the
TOE's Control Panel.
o Security attributes: User Role (defined by Permission Set) and User Identifier
Incoming analog fax phone line users – Unauthenticated entities that initiate and transmit
faxes to the TOE over the TOE’s analog fax phone line connection. These users are considered
U.ADMINISTRATOR because User Document Data (i.e., incoming faxes) created by these users
is considered to be owned by U.ADMINISTRATOR. There are no actual management /
administrative functions available to these users.
o Security attributes: None
IPsec users:
o Network Client Computers – Computers (U.NORMAL entities) that can successfully
authenticate to the TOE's PJL Interface (TCP port 9100) using IPsec and mutual