HP Inc.
HP LaserJet Enterprise MFP M527 Series,
Color LaserJet Enterprise MFP M577 Series, and
PageWide Enterprise Color MFP 586 Series
Firmware with Jetdirect Inside Security Target
Version: 2.0 Copyright © 2008-2016 by atsec information security corporation and HP Inc. Page 78 of 98
Last update: 2016-06-07 or its wholly owned subsidiaries
Security assurance requirement
ASE_OBJ.2 Security objectives
ASE_ECD.1 Extended components
definition
ASE_REQ.2 Derived security
requirements
ASE_TSS.1 TOE summary
specification
ATE_COV.1 Evidence of coverage
ATE_FUN.1 Functional testing
ATE_IND.2 Independent testing -
sample
AVA Vulnerability
assessment
AVA_VAN.2 Vulnerability analysis
Table 34: Security assurance requirements
6.4 Security Assurance Requirements Rationale
The evaluation assurance level has been chosen to match a Basic attack potential commensurate with
the threat environment that is experienced by typical consumers of the TOE and commensurate with
[PP2600.2]. In addition, the evaluation assurance level has been augmented with ALC_FLR.2
commensurate with the augmented flaw remediation capabilities offered by the developer beyond those
required by the evaluation assurance level and commensurate with [PP2600.2].