Konica Minolta C250i bizhub C360i/C300i/C250i Security Operations User Manual - Page 14

Roles and requirements of the administrator, Password usage requirements, External authentication

Page 14 highlights

1.4 Precautions for operation control 1 1.4.2 Roles and requirements of the administrator The administrator should take full responsibility for controlling the machine, thereby ensuring that no improper operations are performed. - A person who is capable of taking full responsibility for controlling the machine should be appointed as the administrator to make sure that no improper operations are performed. - When using an external authentication server, an SMTP server (mail server), a DNS server, an audit log server, a WebDAV server, or an SMB server, each server should be appropriately managed by the administrator and should be periodically checked to confirm that settings have not been changed without permission. 1.4.3 Password usage requirements The administrator must control the Memory RX user box password appropriately so that it may not be leaked. The password should not be one that can be easily guessed. The user, on the other hand, should control the user password appropriately so that it may not be leaked. Again, the password should not be one that can be easily guessed. NOTICE Manage carefully not to forget the administrator password. In the event of a forgotten it, it is necessary to initialize all the data including the hardware. - The administrator of the machine shall never disclose the administrator password to anyone other than the administrator of the machine. - Make sure that the administrator of the machine changes the administrator password regularly. - The administrator must change the Memory RX user box password at regular intervals. - The administrator of the machine should make sure that any number that can easily be guessed from birthdays, employee identification numbers, and the like is not set for the administrator password. - The administrator should make sure that any number that can easily be guessed from birthdays, employee identification numbers, and the like is not set for the Memory RX user box password. - If a User Password has been changed, the administrator should have the corresponding user change the password as soon as possible. - If the administrator password has been changed by the Service Engineer, the administrator of the machine should change the administrator password as soon as possible. - The administrator should have users ensure that the passwords set for the user authentication and the box that can be used by the user are known only by the user concerned. - The administrator should have users change the passwords set for the user authentication at regular intervals. - The administrator of the machine should have the user administrator log on to the user mode and change his or her password in [Utility] - [Utility] - [Information] - [Change User Password] if he or she changes the password. - The administrator should make sure that any user does not set any number that can easily be guessed from birthdays, employee identification numbers, and the like for the passwords set for the user authentication. 1.4.4 External authentication server control requirements The administrator and the server administrator are required to apply patches to, or perform account control for, this machine and the external authentication server connected to the office LAN in which the machine is installed to ensure operation control that achieves appropriate access control. This machine can be used only after the user who uses this machine has been registered in the external authentication server. The server administrator should also check registered users at regular intervals to thereby ensure that any unnecessary users are left registered. bizhub C360i/C300i/C250i/C036DNi/C030DNi/C025DNi 1-10

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106

bizhub C360i/C300i/C250i/C036DNi/C030DNi/C025DNi
1-10
1.4
Precautions for operation control
1
1.4.2
Roles and requirements of the administrator
The administrator should take full responsibility for controlling the machine, thereby ensuring that no improp-
er operations are performed.
-
A person who is capable of taking full responsibility for controlling the machine should be appointed as
the administrator to make sure that no improper operations are performed.
-
When using an external authentication server, an SMTP server (mail server), a DNS server, an audit log
server, a WebDAV server, or an SMB server, each server should be appropriately managed by the ad-
ministrator and should be periodically checked to confirm that settings have not been changed without
permission.
1.4.3
Password usage requirements
The administrator must control the Memory RX user box password appropriately so that it may not be leaked.
The password should not be one that can be easily guessed. The user, on the other hand, should control the
user password appropriately so that it may not be leaked. Again, the password should not be one that can
be easily guessed.
NOTICE
Manage carefully not to forget the administrator password. In the event of a forgotten it, it is necessary to in-
itialize all the data including the hardware.
<To Achieve Effective Security>
-
The administrator of the machine shall never disclose the administrator password to anyone other than
the administrator of the machine.
-
Make sure that the administrator of the machine changes the administrator password regularly.
-
The administrator must change the Memory RX user box password at regular intervals.
-
The administrator of the machine should make sure that any number that can easily be guessed from
birthdays, employee identification numbers, and the like is not set for the administrator password.
-
The administrator should make sure that any number that can easily be guessed from birthdays, em-
ployee identification numbers, and the like is not set for the Memory RX user box password.
-
If a User Password has been changed, the administrator should have the corresponding user change
the password as soon as possible.
-
If the administrator password has been changed by the Service Engineer, the administrator of the ma-
chine should change the administrator password as soon as possible.
-
The administrator should have users ensure that the passwords set for the user authentication and the
box that can be used by the user are known only by the user concerned.
-
The administrator should have users change the passwords set for the user authentication at regular
intervals.
-
The administrator of the machine should have the user administrator log on to the user mode and
change his or her password in [Utility] - [Utility] - [Information] - [Change User Password] if he or she
changes the password.
-
The administrator should make sure that any user does not set any number that can easily be guessed
from birthdays, employee identification numbers, and the like for the passwords set for the user authen-
tication.
1.4.4
External authentication server control requirements
The administrator and the server administrator are required to apply patches to, or perform account control
for, this machine and the external authentication server connected to the office LAN in which the machine is
installed to ensure operation control that achieves appropriate access control.
This machine can be used only after the user who uses this machine has been registered in the external au-
thentication server. The server administrator should also check registered users at regular intervals to thereby
ensure that any unnecessary users are left registered.