Page 43 of 81 
Copyright (c) 2010 RICOH COMPANY, LTD. All Rights Reserved. 
User authentication using TOE from client computer Web browser 
User authentication when printing from client computer 
User authentication when faxing from client computer 
 
FIA_AFL.1.2  When defined number of unsuccessful authentication attempts has been [selection: met], the 
TSF shall  [assignment: Lockout the user, who has failed the authentication attempts, 
until one of the Lockout release actions, shown in Table14, is taken]. 
Table 14: Lockout release actions 
Lockout release actions  Details 
Auto Lockout Release 
If the user fails to authenticate after making the number of attempts 
specified for Lockout release, and the Lockout time (between 1 and 9999 
minutes) set in advance by the machine administrator has elapsed, then 
Lockout will be released upon the first successful identification and 
authentication by the locked-out user. The machine administrator can set 
the Lockout time to indefinite, and in this case, Lockout cannot be released 
by a time-based operation but can be released by an operation other than a 
time-based operation. 
Manual Lockout Release 
Regardless of the time specified for the Lockout release by the machine 
administrator, an unlocking administrator specified for any user role of a 
locked-out user can release a locked-out user. FMT_MTD.1 defines the 
relationship between locked-out user and unlocking administrator. 
There is also a special Lockout release: If an administrator (any role) or a 
supervisor is locked out, restarting the TOE has the same effect as the 
Lockout release operation performed by an unlocking administrator. 
 
FIA_ATD.1  User attribute definition 
Hierarchical to:  No other components. 
Dependencies:  No dependencies. 
FIA_ATD.1.1  The TSF shall maintain the following list of security attributes belonging to individual users: 
[assignment: general user IDs,  document data default ACL, administrator IDs, 
administrator roles and supervisor ID]. 
 
FIA_SOS.1  Verification of secrets 
Hierarchical to:  No other components. 
Dependencies:  No dependencies. 
FIA_SOS.1.1  The TSF shall provide a mechanism to verify that secrets meet [assignment: following 
quality metrics]. 
(1)  Usable characters and its types: 
Upper-case letters: [A-Z] (26 letters) 
Lower-case letters: [a-z] (26 letters)