Xerox  Multi-Function Device Security Target 
 
47 
Copyright
 2013 Xerox Corporation. All rights reserved. 
FDP_ACF.1.1 (FUNC)  The TSF shall enforce the [TOE Function Access 
Control  SFP]  to  objects  based  on  the  following:  [Users 
and their role based permissions to perform any or all of 
the following functions: print, scan, copy, fax, document 
storage  and  retrieval,  access  to  shared-medium 
interface].  
FDP_ACF.1.2 (FUNC)  The  TSF  shall  enforce  the  following  rules  to 
determine if an operation among controlled subjects and 
controlled  objects  is  allowed:  [users  assigned  to  a  role 
that  is  explicitly  authorized  by  U.ADMINISTATOR 
(System  Administrator)  to  use  a  function  is  allowed  to 
access the function].  
FDP_ACF.1.3 (FUNC)  The  TSF  shall  explicitly  authorise  access  of 
subjects  to  objects  based  on  the  following  additional 
rules: [none].  
FDP_ACF.1.4 (FUNC)  The TSF shall explicitly deny access of subjects to 
objects based on the [none].  
Application Note: This SFR is FDP_ACF.1 (b) from The IEEE Std. 2600.2 
PP. 
6.3.4.5.  FDP_IFC.1 (FILTER) Subset information flow control 
Hierarchical to:  No other components. 
Dependencies:  FDP_IFF.1 Simple security attributes 
FDP_IFC.1.1 (FILTER)  The TSF shall enforce the [IPFilter SFP] on [ 
-  Subjects:  External  entities  that  send  traffic  to  the 
TOE; 
-  Information:  All  IP-based  traffic  to/from  that 
source/destination; 
-  Operations: send or receive network traffic]. 
6.3.4.6.  FDP_IFF.1 (FILTER) Simple security attributes 
Hierarchical to:  No other components. 
Dependencies:  FDP_IFC.1 Subset information flow control 
  FMT_MSA.3 Static attribute initialization. 
FDP_IFF.1.1 (FILTER)  The TSF shall enforce the [IPFilter SFP] based on 
the  following  types  of  subject  and  information  security 
attributes: [ 
-  Subjects: External entities that send traffic to the TOE 
o  IP address,