Xerox  Multi-Function Device Security Target 
 
51 
Copyright
 2013 Xerox Corporation. All rights reserved. 
FMT_MSA.3.1 (USER)  The  TSF  shall  enforce  the  [User  Access  Control 
SFP in Table 21] to provide permissive default values for 
security attributes that are used to enforce the SFP. 
FMT_MSA.3.2 (USER)  The  TSF  shall  allow  the  [U.ADMINISTRATOR 
(System Administrator)] to specify alternative initial values 
to  override  the  default  values  when  an  object  or 
information is created. 
Application Note: This SFR is FMT_MSA.3 (a) from The IEEE Std. 2600.2 
PP. 
6.3.6.4.  FMT_MSA.3 (FUNC) Static attribute initialisation 
Hierarchical to:  No other components. 
Dependencies:  FMT_MSA.1 Management of security attributes 
  FMT_SMR.1 Security roles 
FMT_MSA.3.1 (FUNC)  The TSF shall enforce the [TOE Function Access 
Control  Policy]  to  provide  permissive  default  values  for 
security attributes that are used to enforce the SFP. 
FMT_MSA.3.2 (FUNC)  The  TSF  shall  allow  the  [U.ADMINISTRATOR 
(System Administrator)] to specify alternative initial values 
to  override  the  default  values  when  an  object  or 
information is created. 
Application Note: This SFR is FMT_MSA.3 (b) from The IEEE Std. 2600.2 
PP. 
6.3.6.5.  FMT_MTD.1 (MGMT1) Management of TSF data  
Hierarchical to:  No other components. 
Dependencies:  FMT_SMR.1 Security roles 
  FMT_SMF.1 Specification of Management Functions 
FMT_MTD.1.1 (MGMT1)  The TSF shall restrict the ability to [download] the 
[audit  log]  to  [U.ADMINISTRATOR  (System 
Administrator)]. 
Application  Note:  This  SFR  is  part  of  FMT_MTD.1  from  The  IEEE  Std. 
2600.2 PP. 
6.3.6.6.  FMT_MTD.1 (MGMT2) Management of TSF data  
Hierarchical to:  No other components. 
Dependencies:  FMT_SMR.1 Security roles 
  FMT_SMF.1 Specification of Management Functions