Ricoh Aficio MP 3350B Security Target - Page 46

assignment: General User IDs, Document Data Default ACL, Administrator IDs

Page 46 highlights

Manual Lockout Release Page 46 of 83 Regardless of the value set for the Lockout release time by the Machine Administrator, the Unlocking Administrators who are set for each User Role of the Locked out Users can release Locked out Users. FMT_MTD.1 defines the relation between the Locked out Users and Unlocking Administrator. Also, as a special lockout release, if Administrators (all Administrator Roles) and a Supervisor are locked out, restarting the TOE has the same effect as the lockout release operation by the Unlocking Administrator. FIA_ATD.1 User attribute definition Hierarchical to: No other components. Dependencies: No dependencies. FIA_ATD.1.1 The TSF shall maintain the following list of security attributes belonging to individual users: [assignment: General User IDs, Document Data Default ACL, Administrator IDs, Administrator Roles and Supervisor ID]. FIA_SOS.1 Verification of secrets Hierarchical to: No other components. Dependencies: No dependencies. FIA_SOS.1.1 The TSF shall provide a mechanism to verify that secrets meet [assignment: following quality metrics]. (1) Usable letters and its letter types: Upper-case letters: [A-Z] (26 letters) Lower-case letters: [a-z] (26 letters) Numbers: [0-9] (10 letters) Symbols: SP (spaces 33 letters) (2) Registerable digit numbers: For General Users No fewer than the Minimum Password Length set by the User Administrator (8-32 characters), nor more than 128 characters. For Administrators and a Supervisor No fewer than the Minimum Password Length set by the User Administrator (8-32 characters), nor more than 32 characters. (3) Rule: It is allowed to register the passwords composed of a combination of letter types based on the Password Complexity Setting set by the User Administrator. The User Administrator sets either Level 1 or Level 2 for Password Complexity Setting. FIA_UAU.2 User authentication before any action Hierarchical to: FIA_UAU.1 Timing of authentication. Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83

Page 46 of 83
Manual Lockout Release
Regardless of the value set for the Lockout release time by the Machine
Administrator, the Unlocking Administrators who are set for each User
Role of the Locked out Users can release Locked out Users. FMT_MTD.1
defines the relation between the Locked out Users and Unlocking
Administrator.
Also, as a special lockout release, if Administrators (all Administrator
Roles) and a Supervisor are locked out, restarting the TOE has the same
effect as the lockout release operation by the Unlocking Administrator.
FIA_ATD.1
User attribute definition
Hierarchical to:
No other components.
Dependencies:
No dependencies.
FIA_ATD.1.1
The TSF shall maintain the following list of security attributes belonging to individual users:
[assignment: General User IDs, Document Data Default ACL, Administrator IDs,
Administrator Roles and Supervisor ID].
FIA_SOS.1
Verification of secrets
Hierarchical to:
No other components.
Dependencies:
No dependencies.
FIA_SOS.1.1 The TSF shall provide a mechanism to verify that secrets meet
[assignment: following
quality metrics]
.
(1) Usable letters and its letter types:
Upper-case letters: [A-Z] (26 letters)
Lower-case letters: [a-z] (26 letters)
Numbers: [0-9] (10 letters)
Symbols: SP (spaces) ! " # $ % & ' ( ) * + , - . / : ; < = > ? @ [ \ ] ^ _ ` { | } ~ (33 letters)
(2) Registerable digit numbers:
For General Users
No fewer than the Minimum Password Length set by the User Administrator (8-32
characters), nor more than 128 characters.
For Administrators and a Supervisor
No fewer than the Minimum Password Length set by the User Administrator (8-32
characters), nor more than 32 characters.
(3) Rule:
It is allowed to register the passwords composed of a combination of letter types based on
the Password Complexity Setting set by the User Administrator. The User Administrator
sets either Level 1 or Level 2 for Password Complexity Setting.
FIA_UAU.2
User authentication before any action
Hierarchical to:
FIA_UAU.1 Timing of authentication.
Copyright (c) 2009,2010 RICOH COMPANY, LTD. All Rights Reserved.