Certified/Validated Products List

Xerox Color C60/C70
Controller ROM Ver. 1.200.17,
IOT ROM Ver. 67.20.0,
ADF ROM Ver. 13.19.3

Fuji Xerox Co., Ltd.
Last Updated 2015-02-18
Product Name :
Xerox Color C60/C70
Version of TOE :
Controller ROM Ver. 1.200.17,
IOT ROM Ver. 67.20.0,
ADF ROM Ver. 13.19.3
Product Type :
Multi Function Device
Certification No. :
Date :
Version of Common Criteria:
3.1 Release4
Conformance Claim :
EAL3 Augmented with ALC_FLR.2
PP Identifier :
IEEE Std 2600.1™-2009


Description of TOE

The TOE is the Multi Function Device (MFD) that provides such functions as copy, print, scan, and fax.
The TOE is assumed to be used at general office, from the control panel, public telephone line, clients (for general user and system administrator) and servers which are connected to the TOE via internal network, and general user client which is directly connected to the TOE.


TOE security functionality

To ensure the security of assets to be protected, the TOE provides the following security functions regarding the above basic functions:

- Hard Disk Data Overwrite
    A function to overwrite and delete the document data in the internal HDD.
- Hard Disk Data Encryption
    A function to encrypt the document data before the data is stored into the internal HDD.
- User Authentication
    A function to identify and authenticate users and permit the authorized users to use functions. This function also allows only owners of document data and system administrators to handle document data.
- System Administrator's Security Management
    A function to allow only system administrators to configure the settings of security functions.
- Customer Engineer Operation Restriction
    A function to allow only system administrators to configure the settings for restricting customer engineer operations.
- Security Audit Log
    A function to generate audit logs of security events and allow only system administrators to refer to them.
- Internal Network Data Protection
    A function to protect communication data by using encryption communication protocols.
- Information Flow Security
    A function to restrict the unpermitted communication between the TOE interface and internal network.
- Self test
    A function to verify the integrity of TSF executable code and TOE setting data.


Security functional requirements

This TOE implements the following security functional requirements.

Security audit Non-repudiation of origin/receipt Cryptographic functionality Access control
Data authentication Export data protection Information flow control Import data protection
Internal transfer data protection Residual information protection Rollback Stored data integrity
Transfer data confidentiality Transfer data integrity Identification and authentication Security management
Privacy Control Security functionality protection Resource utilisation management TOE access control
Trusted path/channels