Xerox  Multi-Function Device Security Target 
 
26 
Copyright
 2013 Xerox Corporation. All rights reserved. 
O.AUDIT_STORAGE.PRO
TECTED 
The TOE shall ensure that internal audit records are 
protected from unauthorized access, deletion and 
modifications. 
4.2.  Security Objectives for the 
Operational Environment 
This  section  describes  the  security  objectives  that  must  be  fulfilled  by  IT 
methods in the IT environment of the TOE. 
Table 17:  Security objectives for the IT environment 
OE.AUDIT_STORAGE.PROTECTED 
If audit records are exported from the TOE to 
another trusted IT product, the TOE Owner shall 
ensure that those records are protected from 
unauthorized access, deletion and modifications. 
OE.AUDIT_ACCESS.AUTHORIZED 
If audit records generated by the TOE are 
exported from the TOE to another trusted IT 
product, the TOE Owner shall ensure that those 
records can be accessed in order to detect 
potential security violations, and only by 
authorized persons  
The IT environment shall provide protection from 
unmanaged access to TOE external interfaces. 
The IT environment shall provide support for user 
identification and authentication and protect the 
user credentials in transit when TOE operates in 
remote identification and authentication mode.