Ricoh Aficio MP 3350B Security Target - Page 45

assignment: the consecutive

Page 45 highlights

Page 45 of 83 FDP_IFF.1.5 The TSF shall explicitly deny an information flow based on the following rules: [assignment: no rules, based on security attributes, that explicitly deny information flows]. 6.1.4 Class FIA: Identification and authentication FIA_AFL.1 Authentication failure handling Hierarchical to: No other components. Dependencies: FIA_UAU.1 Timing of authentication. FIA_AFL.1.1 TSF shall detect when [selection: an Administrator (refinement: the Machine Administrator) configurable positive integer within [assignment: 1 to 5]] unsuccessful authentication attempts occur related to [assignment: the consecutive numbers of times of authentication failure for each user in the authentication events shown in Table 14]. Table 14: List of Authentication Events Authentication events User authentication using the Control Panel User authentication using the TOE from web browser of client PC User authentication when printing from client PC User authentication when faxing from client PC FIA_AFL.1.2 When defined number of unsuccessful authentication attempts has been [selection: met], the TSF shall [assignment: Lockout the user, who has failed the authentication attempts, until one of the Lockout release actions, shown in Table 15, is taken]. Table 15: Lockout Release Actions Lockout release actions Auto Lockout Release Details If the unsuccessful authentication attempts have met the defined number, and the Lockout time set in advance (by the Machine Administrator between 1 and 9999 minutes) has elapsed, then Lockout is released by the first identification and authentication by the Locked out User. Although the Machine Administrator can also set the Lockout time to an indefinite, in this case, Lockout cannot be released by the Lockout release operation of elapse of time but can only by other Lockout release operations. Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83

Page 45 of 83
FDP_IFF.1.5
The TSF shall explicitly deny an information flow based on the following rules:
[assignment: no rules, based on security attributes, that explicitly deny information
flows]
.
6.1.4
Class FIA: Identification and authentication
FIA_AFL.1
Authentication failure handling
Hierarchical to:
No other components.
Dependencies:
FIA_UAU.1 Timing of authentication.
FIA_AFL.1.1
TSF shall detect when
[selection: an Administrator (refinement: the Machine
Administrator) configurable positive integer within [assignment: 1 to 5]]
unsuccessful authentication attempts occur related to
[assignment: the consecutive
numbers of times of authentication failure for each user in the authentication events
shown in
Table 14
].
Table 14: List of Authentication Events
Authentication events
User authentication using the Control Panel
User authentication using the TOE from web browser of client PC
User authentication when printing from client PC
User authentication when faxing from client PC
FIA_AFL.1.2
When defined number of unsuccessful authentication attempts has been
[selection: met]
, the
TSF shall
[assignment: Lockout the user, who has failed the authentication attempts,
until one of the Lockout release actions, shown in
Table 15
, is taken].
Table 15: Lockout Release Actions
Lockout release actions
Details
Auto Lockout Release
If the unsuccessful authentication attempts have met the defined number,
and the Lockout time set in advance (by the Machine Administrator
between 1 and 9999 minutes) has elapsed, then Lockout is released by the
first identification and authentication by the Locked out User. Although the
Machine Administrator can also set the Lockout time to an indefinite, in
this case, Lockout cannot be released by the Lockout release operation of
elapse of time but can only by other Lockout release operations.
Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.