Specifications
Samsung MFP Security Kit Type_B V1.5 Security Target
81
Copyright
2010 Samsung Electronics Co., Ltd., All rights reserved
of independently assured security, and require a thorough investigation of
the TOE and its development without substantial re-engineering.
To understand security actions, EAL3 provides assurance using the
specifications of function or interface, guidance, and structural
explanation of the TOE structure by analyzing SFR included in a complete
ST. This analysis is supported by independent testing of TSF, the proof of
developer’s test based on the functional specification or the TOE design,
independent confirmation of test result samples by the developer,
vulnerability analyses to ensure the tolerance to the attack based on the
functionality specification, the TOE design, security structure, or guidance.
EAL3 also provides assurance by controlling the development environment,
managing the TOE version control, and proofing a safe releasing process.
5.3.3 Rationale for Dependencies
5.3.3.1 SFR Dependencies
FIA_UAU.2 and FMT_SMR.1 have a subordinate relationship with
FIA_UID.1, but they are satisfied by FIA_UID.2 that is a hierarchical
relationship with FIA_UID.1.
FIA_AFL.1 and FIA_UAU.7 have a subordinate relationship with
FIA_UAU.1, but they are satisfied by FIA_UAU.2 that is a hierarchical
relationship with FIA_UAU.1.
FAU_GEN.1 has a subordinate relationship with FPT_STM.1. But because
the TOE records security events correctly with reliable time-stamps,
FAU_GEN.1 is satisfied by OE.TIME_STAMP of operational environment
instead of FPT_STM.1.
FDP_IFF.1(1) and FDP_IFF.1(2) have a subordinate relationship with
FDP_IFC.1, but they are satisfied by FDP_IFC.2(1), FDP_IFC.2(2) that is a
hierarchical relationship with FDP_IFC.1.
FDP_IFF.1(1) has a subordinate relationship with FMT_MSA.3, but
because the security properties of FDP_IFF.1(2)’s subject (None) and the
security properties of information (fax image standard) are not objects for
management, FMT_MSA.3 is not required.
FDP_IFF.1(2) has a subordinate relationship with FMT_MSA.3, but
because the security properties of FDP_IFF.1(1)’s subject (None) and the
security properties of information (protocol and port) are not objects for
management, FMT_MSA.3 is not required.










