Xerox  Multi-Function Device Security Target 
 
46 
Copyright
 2013 Xerox Corporation. All rights reserved. 
6.3.4.2.  FDP_ACC.1 (FUNC) Subset access control  
Hierarchical to:  No other components. 
Dependencies:  FDP_ACF.1 Security attribute based access control 
FDP_ACC.1.1 (FUNC)  The TSF shall enforce the [TOE Function Access 
Control  SFP]  on  [users  as  subjects,  TOE  functions  as 
objects, and the right to use the functions as operations].  
Application Note: This SFR is FDP_ACC.1 (b) from The IEEE Std. 2600.2 
PP. 
6.3.4.3.  FDP_ACF.1 (USER) Security attribute based access 
control  
Hierarchical to:  No other components. 
Dependencies:  FDP_ACC.1 Subset access control 
  FMT_MSA.3 Static attribute initialisation 
FDP_ACF.1.1 (USER)  The  TSF  shall  enforce  the  [User  Access  Control 
SFP in Table 21] to objects based on the following: [the 
list of users as subjects and objects controlled under the 
User Access Control SFP in Table 21, and for each, the 
indicated security attributes in Table 21].  
FDP_ACF.1.2 (USER)  The  TSF  shall  enforce  the  following  rules  to 
determine if an operation among controlled subjects and 
controlled objects is allowed: [rules specified in the User 
Access Control SFP in Table 21 governing access among 
controlled users as subjects and controlled objects using 
controlled operations on controlled objects].  
FDP_ACF.1.3 (USER)  The  TSF  shall  explicitly  authorise  access  of 
subjects  to  objects  based  on  the  following  additional 
rules: [none].  
FDP_ACF.1.4 (USER)  The TSF shall explicitly deny access of subjects to 
objects based on the [none].  
Application Note: This SFR covers FDP_ACF.1 (a) and FDP_ACF.1 from 
all claimed packages (PRT, SCN, CPY, FAX, DSR) in the IEEE Std. 2600.2 
PP. 
6.3.4.4.  FDP_ACF.1 (FUNC) Security attribute based access 
control  
Hierarchical to:  No other components. 
Dependencies:  FDP_ACC.1 Subset access control 
  FMT_MSA.3 Static attribute initialisation