Xerox  Multi-Function Device Security Target 
 
66 
Copyright
 2013 Xerox Corporation. All rights reserved. 
  
 
3
 The dependency of FDP_IFF.1 (FILTER) on FMT_MSA.3 is not met because none of these functions support “a) 
managing the group of roles that can specify initial values; b) managing the permissive or restrictive setting of default 
values for a given access control SFP; c) management of rules by which security attributes inherit specified values.” 
(CC  Part  2  Page  106).    The  TOE  does  not  give  system  administrators  the  option  of  specifying  default  values, 
permissive or otherwise.  In fact, these features are configured and, with the exception of IP Filter rules, cannot be 
modified  by  the  system  administrator  other  than  to  enable  or  disable  them.    It  is  for  these  reasons  that  the 
dependency on FMT_MSA.3 is not and cannot be expected to be met.