Page 57 of 93
Copyright (c) 2012 RICOH COMPANY, LTD. All rights reserved.
FDP_ACF.1.4(b) The TSF shall explicitly deny access of subjects to objects based on the following additional
rules: [assignment: deny an operation on MFP application in case of supervisor process or
RC Gate process].
FDP_RIP.1 Subset residual information protection
Hierarchical to: No other components.
Dependencies: No dependencies.
FDP_RIP.1.1 The TSF shall ensure that any previous information content of a resource is made unavailable
upon the [selection: deallocation of the resource from] the following objects: [assignment:
user documents].
6.1.4 Class FIA: Identification and authentication
FIA_AFL.1 Authentication failure handling
Hierarchical to: No other components.
Dependencies: FIA_UAU.1 Timing of authentication
FIA_AFL.1.1 The TSF shall detect when [selection: an administrator configurable positive integer within
[assignment: 1 to 5]] unsuccessful authentication attempts occur related to [assignment: the
authentication events of Basic Authentication shown in Table 22].
Table 22 : List of Authentication Events of Basic Authentication
Authentication Events
User authentication using the Operation Panel
User authentication using the TOE from client computer Web
browser
User authentication when printing from the client computer
User authentication when using LAN Fax from client computer
FIA_AFL.1.2 When the defined number of unsuccessful authentication attempts has been [selection: met],
the TSF shall [assignment: perform actions shown in Table 23].
Table 23 : List of Actions for Authentication Failure
Unsuccessfully
Authenticated Users
Actions for Authentication Failure
Normal user The lockout for the normal user is released by the lockout time set by the MFP
administrator, or release operation by the MFP administrator.
Supervisor The lockout for a supervisor is released by the lockout time set by the MFP
administrator, release operation by the MFP administrator, or elapse of a given
time after the TOE's restart.