Konica Minolta bizhub C360 bizhub C220/C280/C360 Security Operations User Guid - Page 10

Precautions for Operation Control - administrator password

Page 10 highlights

1.4 Precautions for Operation Control 1 1.4 Precautions for Operation Control This machine and the data handled by this machine should be used in an office environment that meets the following conditions. The machine must be controlled for its operation under the following conditions to protect the data that should be protected. Roles and Requirements of the Administrator The Administrator should take full responsibility for controlling the machine, thereby ensuring that no improper operations are performed. - A person who is capable of taking full responsibility for controlling the machine should be appointed as the Administrator to make sure that no improper operations are performed. - When using an SMTP server (mail server) or an DNS server, each server should be appropriately man- aged by the Administrator and should be periodically checked to confirm that settings have not been changed without permission. Password Usage Requirements The Administrator must control the Administrator Password, Encryption Key, auth-Password, priv-Password, and WebDAV Server Password appropriately so that they may not be leaked. These passwords should not be ones that can be easily guessed. The user, on the other hand, should control the User Box Password, Secure Print Password, and User Password appropriately so that they may not be leaked. Again, these passwords should not be ones that can be easily guessed. For the Public User Box shared among a number of users, the User Box Password should be appropriately controlled so that it may not be leaked to anyone who is not the user of the Public User Box. - Make absolutely sure that only the Administrator knows the Administrator Password, Encryption Key, auth-Password, priv-Password, and WebDAV Server Password. - The Administrator must change the Administrator Password, Encryption Key, auth-Password, priv- Password, and WebDAV Server Password at regular intervals. - The Administrator should make sure that any number that can easily be guessed from birthdays, em- ployee identification numbers, and the like is not set for the Administrator Password, Account Password, Encryption Key, auth-Password, priv-Password, and WebDAV Server Password. - If a User Password or User Box Password has been changed, the Administrator should have the corresponding user change the password as soon as possible. - The Administrator should change the Account Password set for each account at regular intervals and, should one be changed, he or she should immediately inform users who implement Account Track of the new Account Password. - If the Administrator Password has been changed by the Service Engineer, the Administrator should change the Administrator Password as soon as possible. - The Administrator should have users ensure that the passwords set for the User Authentication, Secure Print, and User Box are known only by the user concerned. - The Administrator should have users who implement Account Authentication ensure that the Account Password set for the account is known by the users implementing Account Authentication only. - The Administrator should make sure that only the users who share a Public User Box and Group User Box know the password set for it. - The Administrator should have users change the passwords set for the User Authentication and User Box at regular intervals. - The Administrator should make sure that any user does not set any number that can easily be guessed from birthdays, employee identification numbers, and the like for the passwords set for the User Authentication, Secure Print, and User Box. bizhub C360/C280/C220 1-6

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183

bizhub C360/C280/C220
1-6
1.4
Precautions for Operation Control
1
1.4
Precautions for Operation Control
This machine and the data handled by this machine should be used in an office environment that meets the
following conditions. The machine must be controlled for its operation under the following conditions to pro-
tect the data that should be protected.
Roles and Requirements of the Administrator
The Administrator should take full responsibility for controlling the machine, thereby ensuring that no improp-
er operations are performed.
<To Achieve Effective Security>
-
A person who is capable of taking full responsibility for controlling the machine should be appointed as
the Administrator to make sure that no improper operations are performed.
-
When using an SMTP server (mail server) or an DNS server, each server should be appropriately man-
aged by the Administrator and should be periodically checked to confirm that settings have not been
changed without permission.
Password Usage Requirements
The Administrator must control the Administrator Password, Encryption Key, auth-Password, priv-Password,
and WebDAV Server Password appropriately so that they may not be leaked. These passwords should not
be ones that can be easily guessed. The user, on the other hand, should control the User Box Password,
Secure Print Password, and User Password appropriately so that they may not be leaked. Again, these pass-
words should not be ones that can be easily guessed. For the Public User Box shared among a number of
users, the User Box Password should be appropriately controlled so that it may not be leaked to anyone who
is not the user of the Public User Box.
<To Achieve Effective Security>
-
Make absolutely sure that only the Administrator knows the Administrator Password, Encryption Key,
auth-Password, priv-Password, and WebDAV Server Password.
-
The Administrator must change the Administrator Password, Encryption Key, auth-Password, priv-
Password, and WebDAV Server Password at regular intervals.
-
The Administrator should make sure that any number that can easily be guessed from birthdays, em-
ployee identification numbers, and the like is not set for the Administrator Password, Account Pass-
word, Encryption Key, auth-Password, priv-Password, and WebDAV Server Password.
-
If a User Password or User Box Password has been changed, the Administrator should have the cor-
responding user change the password as soon as possible.
-
The Administrator should change the Account Password set for each account at regular intervals and,
should one be changed, he or she should immediately inform users who implement Account Track of
the new Account Password.
-
If the Administrator Password has been changed by the Service Engineer, the Administrator should
change the Administrator Password as soon as possible.
-
The Administrator should have users ensure that the passwords set for the User Authentication, Secure
Print, and User Box are known only by the user concerned.
-
The Administrator should have users who implement Account Authentication ensure that the Account
Password set for the account is known by the users implementing Account Authentication only.
-
The Administrator should make sure that only the users who share a Public User Box and Group User
Box know the password set for it.
-
The Administrator should have users change the passwords set for the User Authentication and User
Box at regular intervals.
-
The Administrator should make sure that any user does not set any number that can easily be guessed
from birthdays, employee identification numbers, and the like for the passwords set for the User Au-
thentication, Secure Print, and User Box.