HP Inc.
HP LaserJet Enterprise MFP M527 Series,
Color LaserJet Enterprise MFP M577 Series, and
PageWide Enterprise Color MFP 586 Series
Firmware with Jetdirect Inside Security Target
Version: 2.0 Copyright © 2008-2016 by atsec information security corporation and HP Inc. Page 43 of 98
Last update: 2016-06-07 or its wholly owned subsidiaries
Rationale for security objectives
authentication as the basis for authorization.
OE.USER.AUTHORIZED which establishes responsibility of the TOE Owner to
appropriately grant authorization.
The threat:
User Function Data may be altered by unauthorized persons.
is countered by:
O.FUNC.NO_ALT which protects D.FUNC from unauthorized alteration.
O.USER.AUTHORIZED which establishes user identification and
authentication as the basis for authorization.
OE.USER.AUTHORIZED which establishes responsibility of the TOE Owner to
appropriately grant authorization.
The threat:
TSF Protected Data may be altered by unauthorized persons.
is countered by:
O.PROT.NO_ALT which protects D.PROT from unauthorized alteration.
O.USER.AUTHORIZED which establishes user identification and
authentication as the basis for authorization.
OE.USER.AUTHORIZED which establishes responsibility of the TOE Owner to
appropriately grant authorization.
The threat:
TSF Confidential Data may be disclosed to unauthorized persons.
is countered by:
O.CONF.NO_DIS which protects D.CONF from unauthorized disclosure.
O.USER.AUTHORIZED which establishes user identification and
authentication as the basis for authorization.
OE.USER.AUTHORIZED which establishes responsibility of the TOE Owner to
appropriately grant authorization.
The threat:
TSF Confidential Data may be altered by unauthorized persons.
is countered by:
O.CONF.NO_ALT which protects D.CONF from unauthorized alteration.
O.USER.AUTHORIZED which establishes user identification and
authentication as the basis for authorization.
OE.USER.AUTHORIZED which establishes responsibility of the TOE Owner to