HP Inc.
HP LaserJet Enterprise MFP M527 Series,
Color LaserJet Enterprise MFP M577 Series, and
PageWide Enterprise Color MFP 586 Series
Firmware with Jetdirect Inside Security Target
Version: 2.0 Copyright © 2008-2016 by atsec information security corporation and HP Inc. Page 72 of 98
Last update: 2016-06-07 or its wholly owned subsidiaries
accordance with security policies.
is met by:
FIA_UAU.1 and FIA_UAU.2 which enforce management of
external interfaces by requiring user authentication.
FIA_UID.1 and FIA_UID.2 which enforce management of
external interfaces by requiring user identification.
FMT_MOF.1-faxarchive which allows the administrator to allow
or disallow use of the Fax Archive feature.
FPT_FDI_EXP.1 which enforces management of external
interfaces by requiring (as needed) administrator control of data
transmission from external Interfaces to Shared-medium
Interfaces.
FTA_SSL.3 which enforces management of external interfaces
by terminating inactive sessions.
The objective:
The TOE shall protect TSF Protected Data from unauthorized
alteration.
is met by:
FCS_CKM.1 which specifies the type of cryptographic keys
generated by the TOE for use with HMAC algorithms in IPsec.
FCS_CKM.2 which specifies the cryptographic key distribution
methods used by the TOE in IKEv1 and IKEv2 in IPsec.
FCS_COP.1-ipsec which specifies the RSA decryption algorithm
and the HMAC algorithms used by the TOE in IPsec.
FIA_UID.1 and FIA_UID.2 which support access control and
security roles by requiring user identification.
FMT_MOF.1-auth which specifies the roles that can manage the
selection of sign in methods.
FMT_MTD.1-auth and FMT_MTD.1-users which enforce
protection by restricting access.
FMT_SMF.1 which supports control of security attributes by
requiring functions to control attributes.
FMT_SMR.1 which supports control of security attributes by
requiring security roles.
FTP_ITC.1 which enforces protection by requiring the use of
trusted channels for communication of data over Shared-medium
Interfaces.
The objective:
The TOE shall provide procedures to self-verify executable code