Dell C7765DN MFP Color Laser Printer User Manual

Browse online or download User Manual for Printers Dell C7765DN MFP Color Laser Printer. Dell C7765DN MFP Color Laser Printer User Manual

  • Download
  • Add to my manuals
  • Print

Summary of Contents

Page 1 - Security Target

September 2014 Dell C7765dn Color Multifunction Printer Security Target Version 1.1.3 This document is a translation

Page 2 - - Table of Contents

Dell C7765dn Security Target - 6 - document. When the client is connected to the MFD directly via USB and printer/fax driver is installed to the clie

Page 3

Dell C7765dn Security Target - 7 - (11) USB Media The USB Media is used for printing data stored in the USB Media and for storing scanned data. The

Page 4

Dell C7765dn Security Target - 8 - 1.4. TOE Description This section describes user assumptions and logical/physical scope of this TOE. 1.4.1. User

Page 5 - 1. ST INTRODUCTION

Dell C7765dn Security Target - 9 - Figure 2: MFD Units and TOE Logical Scope 1.4.2.1. Basic Functions As shown in Table 3

Page 6

Dell C7765dn Security Target - 10 - IOT according to the general user’s instruction from the control panel. When more than one copy of an original is

Page 7

Dell C7765dn Security Target - 11 - Function setting data. For this, a system administrator must be authenticated by his/her ID and password entered

Page 8

Dell C7765dn Security Target - 12 - document data in the internal HDD by an attacker who is impersonating an authorized user: ・ The Store Print fu

Page 9

Dell C7765dn Security Target - 13 - panel or to use Smart Card (CAC/PIV). When the user is authenticated, the data on the waiting list corresponding

Page 10

Dell C7765dn Security Target - 14 - ・ Refer to and set the User Authentication; ・ Refer to and set the Store Print; ・ Refer to and set the date an

Page 11 - (11) USB Media

Dell C7765dn Security Target - 15 - ・ SNMP v3 ・ S/MIME (8) Fax Flow Security A Fax board is an option and is connected to TOE controller board vi

Page 12 - 1.4. TOE Description

i - Table of Contents - 1. ST INTRODUCTION ... 1 1.1. ST Reference ...

Page 13 - Basic Functions

Dell C7765dn Security Target - 16 - ・ Self Test Set to [Enabled]

Page 14

Dell C7765dn Security Target - 17 - 1.4.3. Physical Scope and Boundary The physical scope of this TOE is the MFD. Figure 4 shows configuration of ea

Page 15 - Security Functions

Dell C7765dn Security Target - 18 - IOT board. The control panel is a panel on which buttons, lamps, and a touch screen panel are mounted to use and

Page 16 - Network Scan

Dell C7765dn Security Target - 19 - 2. CONFORMANCE CLAIMS 2.1. CC Conformance Claims This ST and TOE conform to the following evaluation standards

Page 17

Dell C7765dn Security Target - 20 - 3. SECURITY PROBLEM DEFINITION This chapter describes the threats, organizational security policies, and the ass

Page 18

Dell C7765dn Security Target - 21 - Figure 5: Assets under and not under Protection Note) The data stored in a general client

Page 19

Dell C7765dn Security Target - 22 - Categories of TOE Setting Data (Note) Data on access denial due to authentication failures of system administrato

Page 20 - Set to [Enabled]

Dell C7765dn Security Target - 23 - 3.2. Organizational Security Policies Table 6 below describes the organizational security policy the TOE must co

Page 21 - Management

Dell C7765dn Security Target - 24 - 4. SECURITY OBJECTIVES This chapter describes the security objectives for the TOE and for the environment and th

Page 22

Dell C7765dn Security Target - 25 - 4.2. Security Objectives for the Environment Table 9 defines the security objectives for the TOE environment. Ta

Page 23 - 2. CONFORMANCE CLAIMS

ii 6. SECURITY REQUIREMENTS ... 30 6.1. Security Functional Requirements ...

Page 24 - 3.1. Threats

Dell C7765dn Security Target - 26 - Security Problems Security Objectives A.ADMIN A.USER A.SECMODE A.ACCESS T.RECOVER T.CONFDATA T.COMM_TAP T.DA

Page 25 - Internally Stored Data

Dell C7765dn Security Target - 27 - Security Problem Security Objectives Rationale T.RECOVER By satisfying the following objective, T.RECOVER can be

Page 26

Dell C7765dn Security Target - 28 - Security Problem Security Objectives Rationale T.DATA_SEC By satisfying the following objectives, T.DATA_SEC can

Page 27 - 3.3. Assumptions

Dell C7765dn Security Target - 29 - 5. EXTENDED COMPONENTS DEFINITION 5.1. Extended Components This ST conforms to CC Part 2 and CC Part 3, and the

Page 28 - 4. SECURITY OBJECTIVES

Dell C7765dn Security Target - 30 - 6. SECURITY REQUIREMENTS This chapter describes the security functional requirements, security assurance require

Page 29

Dell C7765dn Security Target - 31 - authenticated general user’s instruction from the control panel. Used document data stored in the internal HDD Th

Page 30

Dell C7765dn Security Target - 32 - General User identifier User ID and password used to authenticate and identify general user. SA identifier Us

Page 31

Dell C7765dn Security Target - 33 - Data on ID of key operator ID data for key operator authentication. Included in the TOE setting data. Data on pa

Page 32

Dell C7765dn Security Target - 34 - Data on Hard Disk Data Encryption The data on whether to enable/disable the functions related to Hard Disk Data E

Page 33 - 5.1. Extended Components

Dell C7765dn Security Target - 35 - 6.1. Security Functional Requirements Security functional requirements which the TOE offers are described below

Page 34 - 6. SECURITY REQUIREMENTS

iii - List of Figures and Tables - Figure 1: General Operational Environment ... 5 Figure 2:

Page 35

Dell C7765dn Security Target - 36 - private keys). FCS_COP.1 a) Minimal: Success and failure, and the type of cryptographic operation. b) Basic:

Page 36

Dell C7765dn Security Target - 37 - FIA_UAU.1 a) Minimal: Unsuccessful use of the authentication mechanism; b) Basic: All use of the authentication

Page 37

Dell C7765dn Security Target - 38 - administrator mode FMT_SMR.1 a) Minimal: modifications to the group of users that are part of a role; b) Det

Page 38

Dell C7765dn Security Target - 39 - [assignment: authorized users] - system administrator [assignment: list of audit information] - all log info

Page 39

Dell C7765dn Security Target - 40 - [assignment: other actions to be taken in case of audit storage failure] - no other actions to be taken 6.1.

Page 40

Dell C7765dn Security Target - 41 - - 256bits [assignment: list of cryptographic operations] - encryption of the document data and security audit log

Page 41

Dell C7765dn Security Target - 42 - Store Print Deletion of document data Retrieval of document data FDP_ACF.1 Security attribute based access c

Page 42

Dell C7765dn Security Target - 43 - created. - Deletion of Personal Mailbox When the general user identifier and SA identifier of the general user

Page 43

Dell C7765dn Security Target - 44 - attributes, that explicitly deny access of subjects to objects]. [assignment: rules, based on security attribut

Page 44

Dell C7765dn Security Target - 45 - - Fax information flow control SFP [assignment: list of subjects and information controlled under the indicated S

Page 45

Dell C7765dn Security Target - 1 - 1. ST INTRODUCTION This chapter describes Security Target (ST) Reference, TOE Reference, TOE Overview, and TOE De

Page 46

Dell C7765dn Security Target - 46 - Hierarchical to: No other components Dependencies: No dependencies FDP_RIP.1.1 The TSF shall ensure that any

Page 47

Dell C7765dn Security Target - 47 - operation until the main unit is cycled. FIA_AFL.1(2) Authentication failure handling Hierarchical to: No o

Page 48

Dell C7765dn Security Target - 48 - [selection: [assignment: positive integer number] , an administrator configurable positive integer within [assign

Page 49

Dell C7765dn Security Target - 49 - - met [assignment: list of actions] - have the control panel to display the message of “authentication was failed

Page 50

Dell C7765dn Security Target - 50 - FIA_UAU.7.1 The TSF shall provide only [assignment: list of feedback] to the user while the authentication is i

Page 51

Dell C7765dn Security Target - 51 - [assignment: rules for the changing of attributes]. [assignment: rules for the changing of attributes]. - none

Page 52

Dell C7765dn Security Target - 52 - Self Test enable, disable Key operator, SA FMT_MSA.1 Management of security attributes Hierarchical to:

Page 53

Dell C7765dn Security Target - 53 - Store Print owner identifier query, delete Key operator, SA , General userAll Store Print owner identifier que

Page 54

Dell C7765dn Security Target - 54 - modify, delete, clear, [assignment: other operations]] the [assignment: list of TSF data] to [assignment: the aut

Page 55 - Roles

Dell C7765dn Security Target - 55 - Data on Customer Engineer Operation Restriction query, modify Key operator, SA Data on Hard Disk Data Encryption

Page 56

Dell C7765dn Security Target - 2 - Table 1: Function Types and Functions Provided by the TOE Function types Functions provided by the TOE Basic Fu

Page 57

Dell C7765dn Security Target - 56 - explicit access based decisions. Reason: Access is restricted and does not need to be managed. FDP_RIP.1 a) The

Page 58

Dell C7765dn Security Target - 57 - interact with the functions in the TSF; Customer Engineer Operation Restriction FMT_MSA.1 a) managing the group

Page 59

Dell C7765dn Security Target - 58 - 6.1.6. Class FPT: Protection of the TSF FPT_STM.1 Reliable time stamps Hierarchical to: No other compone

Page 60

Dell C7765dn Security Target - 59 - 6.1.7. Class FTP: Trusted path/channels FTP_TRP.1 Trusted path Hierarchical to: No other components.

Page 61

Dell C7765dn Security Target - 60 - 6.2. Security Assurance Requirements The requirements for the TOE security assurance are described in Table 22.

Page 62

Dell C7765dn Security Target - 61 - 6.3. Security Requirement Rationale 6.3.1. Security Functional Requirements Rationale Table 23 lists security f

Page 63

Dell C7765dn Security Target - 62 - Security Objectives Security Functional Requirements O.AUDITS O.CIPHER O.COMM_SEC O.FAX_SEC O.MANAGE O.RESIDU

Page 64

Dell C7765dn Security Target - 63 - Security Objectives Security Functional Requirements Rationale log file. By FPT_STM.1, the auditable events ar

Page 65

Dell C7765dn Security Target - 64 - Security Objectives Security Functional Requirements Rationale local authentication) reaches the defined number

Page 66

Dell C7765dn Security Target - 65 - Security Objectives Security Functional Requirements Rationale By FIA_UAU.7, unauthorized disclosure of the auth

Page 67

Dell C7765dn Security Target - 3 - 1.3.1.3. Usage and Major Security Features of TOE The TOE is mainly used to perform the following functions: ・ C

Page 68

Dell C7765dn Security Target - 66 - Security Objectives Security Functional Requirements Rationale By FMT_SMR.1, the role of general user and system

Page 69

Dell C7765dn Security Target - 67 - Functional Requirement Dependencies of Functional Requirements Requirement and its name Requirement that is depe

Page 70

Dell C7765dn Security Target - 68 - Functional Requirement Dependencies of Functional Requirements Requirement and its name Requirement that is depe

Page 71

Dell C7765dn Security Target - 69 - Functional Requirement Dependencies of Functional Requirements Requirement and its name Requirement that is depe

Page 72

Dell C7765dn Security Target - 70 - 7. TOE SUMMARY SPECIFICATION This chapter describes the summary specifications of the security functions provide

Page 73

Dell C7765dn Security Target - 71 - Security Functions Security Functional Requirements TSF_IOW TSF_CIPHER TSF_USER_AUTH TSF_FMT TSF_CE_LIMIT TSF

Page 74 - 7.1. Security Functions

Dell C7765dn Security Target - 72 - the system administrator mode, the document data and security audit log data are encrypted before stored into the

Page 75

Dell C7765dn Security Target - 73 - Function to retrieve document data from Mailbox. c) Functions controlled by Configuration Web Tool Display of

Page 76

Dell C7765dn Security Target - 74 - authentication which is performed before using the MFD functions. When the entered password does not match the on

Page 77

Dell C7765dn Security Target - 75 - With the authenticated ID, TOE associates the roles of key operator, SA, and general user with the subjects.

Page 78

Dell C7765dn Security Target - 4 - authenticates users. A user needs to enter his/her ID and password from the fax driver, Network Scan Utility, or W

Page 79

Dell C7765dn Security Target - 76 - FDP_ACF.1 Security attribute based access control With the user authentication function, the TOE permits the auth

Page 80

Dell C7765dn Security Target - 77 - document data can be scanned from IIT and stored into the internal HDD according to the user’s instruction from t

Page 81

Dell C7765dn Security Target - 78 - 7.1.4. System Administrator’s Security Management (TSF_FMT) To grant a privilege to a specific user, this functi

Page 82

Dell C7765dn Security Target - 79 - With Configuration Web Tool, the settings of the following TOE security functions can be referred to and changed

Page 83

Dell C7765dn Security Target - 80 - from referring to / changing the settings related to System Administrator’s Security Management (TSF_FMT). This f

Page 84

Dell C7765dn Security Target - 81 - Logged Events Description Status Shutdown requested User operation (Local) Start/End Self Test Successful/Fai

Page 85

Dell C7765dn Security Target - 82 - (2) FAU_SAR.1 Audit review It is assured that all the information recorded in the audit log can be retrieved. Se

Page 86

Dell C7765dn Security Target - 83 - the communication data from modification or disclosure. a) SSL/TLS According to the SSL/TLS communication which

Page 87

Dell C7765dn Security Target - 84 - Cryptographic key generated as IPSec (ESP: Encapsulating Security Payload) at every session Specifically, one of

Page 88

Dell C7765dn Security Target - 85 - Secret-key cryptographic method generated as S/MIME for every mail Cryptographic Method and Size of Secret Key 3

Page 89

Dell C7765dn Security Target - 5 - Figure 1: General Operational Environment 1.3.3. Required Non-TOE Hardware and Softwar

Page 90 - 8. ACRONYMS AND TERMINOLOGY

Dell C7765dn Security Target - 86 - 8. ACRONYMS AND TERMINOLOGY 8.1. Acronyms The following acronyms are used in this ST: Acronym Definition ADF

Page 91 - 8.2. Terminology

Dell C7765dn Security Target - 87 - 8.2. Terminology The following terms are used in this ST: Term Definition User Any entity outside the TOE who

Page 92

Dell C7765dn Security Target - 88 - Term Definition Print Data The data written in PDL, a readable format for MFD, which are to be converted into bi

Page 93

Dell C7765dn Security Target - 89 - Term Definition of users, access denial due to authentication failure of system administrator, Internal Network

Page 94

Dell C7765dn Security Target - 90 - Term Definition stored in Smart Card (CAC/PIV). OCSP Server The OCSP (Online Certificate Status Protocol) is a p

Page 95 - 9. REFERENCES

Dell C7765dn Security Target - 91 - 9. REFERENCES The following documentation was used to prepare this ST. Short Name Document Title [CC Part 1] P

Comments to this Manuals

No comments