Konica Minolta C300i bizhub C360i/C300i/C250i Security Operations User Manual - Page 15

Security function operation setting operating requirements, Operation and control of the machine

Page 15 highlights

1.4 Precautions for operation control 1 1.4.5 Security function operation setting operating requirements The administrator should observe the following operating conditions. - The administrator should make sure that the machine is operated with the settings described in the in- stallation checklist made properly in advance. - The administrator should make sure of correct operation control so that the machine is used with the [Enhanced Security Mode] set to [ON]. - When the [Enhanced Security Mode] is turned [OFF], the administrator is to make various settings ac- cording to the installation checklist and then set the [Enhanced Security Mode] to [ON] again. For details of settings made by the service engineer, contact your service representative. 1.4.6 Operation and control of the machine The administrator should perform the following operation control. - The administrator should log off from the Administrator Mode whenever the operation in the Administrator Mode is completed. The administrator of the machine should also make sure that each individual user logs off from the user authentication mode after the operation in the user authentication mode is completed, including operation of the user box and user box file. - During user registration and box registration, the administrator should make sure that the correct settings are made for the correct users, including functional restrictions and box attributes. - The administrator should appropriately manage the device certificate (IPsec communication certificate) and CA (certification authority) certificate for IPsec communication that have been registered in the machine. - The administrator should ensure that no illegal connection or access is attempted when the machine is to be connected to an external interface. - The administrator should appropriately manage the files containing the job log (audit log) data that has been stored in (distributed to) the server, as well as ensure that only the administrator of the machine handles such files. - The administrator should check the job log (audit log) data at appropriate timing, thereby determining whether a security compromise or a faulty condition has occurred during an operating period. - The administrator should make sure that each individual user updates the OS of the user's terminal and applications installed in it to eliminate any vulnerabilities. - The administrator should delete cache following the procedure specified for each browser when seeing previews on a web browser because the contents can be cached on PCs and make sure that users perform the same procedure. - The administrator should not permit the service engineer to set CS Remote Care. If connection is received from the CS Remote Care center while CS Remote Care is not set, an error (R82) is displayed on the machine panel. - The administrator should check the fax reception status/user status of accessing the MFP and detect any possibility of attack by checking the audit log. The administrator disables the following functions and operates and manages the machine under a condition in which those functions are disabled. Function Name Account Track Settings User Box Save Setting IP Filtering LLMNR Setting WINS/NetBIOS IP Address Fax Function * Setting Procedure Using [Administrator] - [User Auth/Account Track] - [General Settings], set [Account Track Registration] to [OFF]. Using [Administrator] - [Store Address], do not set [Address Book] to [User Box]. Using [Administrator] - [Network] - [TCP/IP Setting], set [Filtering Type] to Using [No Filtering]. Using [Administrator] - [Network] - [TCP/IP Setting] - [TCP/IP Settings1] [DNS Host], set [LLMNR Setting] to [OFF]. Using [Administrator] - [Network] - [SMB Setting], set [WINS/NetBIOS Settings] to [OFF]. Using [Administrator] - [Network] - [Network Fax Settings] - [Network Fax Function Settings], set [IP Address Fax Function] to [OFF]. bizhub C360i/C300i/C250i/C036DNi/C030DNi/C025DNi 1-11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106

bizhub C360i/C300i/C250i/C036DNi/C030DNi/C025DNi
1-11
1.4
Precautions for operation control
1
1.4.5
Security function operation setting operating requirements
The administrator should observe the following operating conditions.
-
The administrator should make sure that the machine is operated with the settings described in the in-
stallation checklist made properly in advance.
-
The administrator should make sure of correct operation control so that the machine is used with the
[Enhanced Security Mode] set to [ON].
-
When the [Enhanced Security Mode] is turned [OFF], the administrator is to make various settings ac-
cording to the installation checklist and then set the [Enhanced Security Mode] to [ON] again. For details
of settings made by the service engineer, contact your service representative.
1.4.6
Operation and control of the machine
The administrator should perform the following operation control.
-
The administrator should log off from the Administrator Mode whenever the operation in the Adminis-
trator Mode is completed. The administrator of the machine should also make sure that each individual
user logs off from the user authentication mode after the operation in the user authentication mode is
completed, including operation of the user box and user box file.
-
During user registration and box registration, the administrator should make sure that the correct set-
tings are made for the correct users, including functional restrictions and box attributes.
-
The administrator should appropriately manage the device certificate (IPsec communication certificate)
and CA (certification authority) certificate for IPsec communication that have been registered in the ma-
chine.
-
The administrator should ensure that no illegal connection or access is attempted when the machine is
to be connected to an external interface.
-
The administrator should appropriately manage the files containing the job log (audit log) data that has
been stored in (distributed to) the server, as well as ensure that only the administrator of the machine
handles such files.
-
The administrator should check the job log (audit log) data at appropriate timing, thereby determining
whether a security compromise or a faulty condition has occurred during an operating period.
-
The administrator should make sure that each individual user updates the OS of the user's terminal and
applications installed in it to eliminate any vulnerabilities.
-
The administrator should delete cache following the procedure specified for each browser when seeing
previews on a web browser because the contents can be cached on PCs and make sure that users
perform the same procedure.
-
The administrator should not permit the service engineer to set CS Remote Care. If connection is re-
ceived from the CS Remote Care center while CS Remote Care is not set, an error (R82) is displayed
on the machine panel.
-
The administrator should check the fax reception status/user status of accessing the MFP and detect
any possibility of attack by checking the audit log.
The administrator disables the following functions and operates and manages the machine under a condition
in which those functions are disabled.
Function Name
Setting Procedure
Account Track Settings
Using [Administrator] - [User Auth/Account Track] - [General Settings],
set [Account Track Registration] to [OFF].
User Box Save Setting
Using [Administrator] - [Store Address], do not set [Address Book] to [Us-
er Box].
IP Filtering
Using [Administrator] - [Network] - [TCP/IP Setting], set [Filtering Type] to
Using [No Filtering].
LLMNR Setting
Using [Administrator] - [Network] - [TCP/IP Setting] - [TCP/IP Settings1] -
[DNS Host], set [LLMNR Setting] to [OFF].
WINS/NetBIOS
Using [Administrator] - [Network] - [SMB Setting], set [WINS/NetBIOS
Settings] to [OFF].
IP Address Fax Function *
Using [Administrator] - [Network] - [Network Fax Settings] - [Network Fax
Function Settings], set [IP Address Fax Function] to [OFF].