Konica Minolta bizhub C360 bizhub C220/C280/C360 PKI Security Operations User - Page 6

and Personal Identity Verification PIV. - support

Page 6 highlights

bizhub C360/C280/C220 for PKI Card System Security Function 4. Precautions for operation control Security Function Ver. 1.02 Jul. 2010 B. Protection of setting data in Service Mode The CE password used to access Service Mode must be adequately controlled by the service engineer concerned to ensure that it is not leaked. Make sure that any password that could be easily guessed by a third person is not used as the CE password. The CE password should: • Not be one that is easily guessed by third persons. • Not be known by any third person. • Be changed at regular intervals. • Be set again quickly if one has been initialized. C. Operating conditions for the IC card and IC card reader The machine supports the following types of IC card and IC card reader. • The types of IC cards supported by the machine are the Common Access Card (CAC) and Personal Identity Verification (PIV). • The type of IC card reader supported by the machine is AU-211P. D. Network connection requirements for the machine If the LAN is to be connected to an outside network, no unauthorized attempt to establish connection from the external network should be permitted. • If the LAN, in which the machine is installed, is connected to an outside network, install a firewall or similar network device to block any access to the machine from the outside network and make the necessary settings. E. Machine maintenance control When the service engineer performs maintenance service jobs for the machine, he or she should check the firmware version number and the checksum value, and make sure that the system has not been altered. F. Miscellaneous The service engineer should explain to the administrator of the machine that the languages, in which the contents of the User's Guide [Security Operations] have been evaluated, is English. He or she should also explain the way how to get the manual in the language, in which it is evaluated. In addition, the service engineer should promptly provide the version of the User's Guide that has been evaluated for the user whenever the user needs one. 2

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41

4. Precautions for operation control
Security Function Ver. 1.02 Jul. 2010
2
bizhub C360/C280/C220
for PKI Card System
Security Function
B.
Protection of setting data in Service Mode
The CE password used to access Service Mode must be adequately controlled by the ser-
vice engineer concerned to ensure that it is not leaked. Make sure that any password that
could be easily guessed by a third person is not used as the CE password.
<To achieve effective security>
The CE password should:
Not be one that is easily guessed by third persons.
Not be known by any third person.
Be changed at regular intervals.
Be set again quickly if one has been initialized.
C.
Operating conditions for the IC card and IC card reader
The machine supports the following types of IC card and IC card reader.
The types of IC cards supported by the machine are the Common Access Card (CAC)
and Personal Identity Verification (PIV).
The type of IC card reader supported by the machine is AU-211P.
D.
Network connection requirements for the machine
If the LAN is to be connected to an outside network, no unauthorized attempt to establish
connection from the external network should be permitted.
<To achieve effective security>
If the LAN, in which the machine is installed, is connected to an outside network, install a
firewall or similar network device to block any access to the machine from the outside
network and make the necessary settings.
E.
Machine maintenance control
When the service engineer performs maintenance service jobs for the machine, he or she
should check the firmware version number and the checksum value, and make sure that
the system has not been altered.
F.
Miscellaneous
The service engineer should explain to the administrator of the machine that the lan-
guages, in which the contents of the User’s Guide [Security Operations] have been evalu-
ated, is English. He or she should also explain the way how to get the manual in the
language, in which it is evaluated.
In addition, the service engineer should promptly provide the version of the User’s Guide
that has been evaluated for the user whenever the user needs one.