Specifications
Samsung MFP Security Kit Type_B V1.5 Security Target
86
Copyright
2010 Samsung Electronics Co., Ltd., All rights reserved
overwriting job. Because the audit records are only available to the
authorized web administrators, unauthorized users cannot change or
delete them. Audit records can be downloaded by using the Web interface
for review and analysis. When storage is full of log data, the latest records
overwrite the oldest audit records.
Relevant SFR : FAU_GEN.1, FAU_SAR.1, FAU_SAR.2, FAU_STG.1,
FAU_STG.4,
6.1.3 Security Management (TSF_FMT)
The TOE accomplishes security management for security function, TSF
data, and security attribute. Only authorized web/local/telnet
administrators can manage the security functions.
The available security functions for each user’s role are displayed in Table
18. Web administrators can manage the following functions: enable or
disable security audit function, download security audit log, change the
account of a web administrator, etc. Local administrators can manage the
following functions: change PIN of local administrator,
enable/disable/start/stop the image overwriting function, etc. General
users can perform the following functions: configure security printing on
the preserved files on the hard disk drive. Telnet administrators can
manage the following functions: inquire and change network setting
values.
TSF data that is stated in Table 19: Authentication information of local
administrator, Authentication information of web administrator,
authentication information of telnet administrator, enable or disable
Automatic Image Overwrite setting value for local administrator, enable
or disable security audit setting value for web administrator.
Only authorized web administrators can download the TOE security audit
record by using the web user interface through “Save as Text File”. Once
the web administrator has successfully logged on to the TOE, the security
audit log can be downloaded.
Table 17 : The TOE Security Function, Relation action and Role
Security Function Action Role
Enable security audit
function
Disable, Enable Web administrator
Download security audit
log
Determine the behavior
of
Web administrator










