Information processing device, control method for information processing device, and program
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2022-08-04
- Publication Date
- 2026-08-03
AI Technical Summary
【0008】 本発明によれば、情報処理装置に設定されたセキュリティポリシーに応じた設定値を設定するセキュリティポリシー機能と、推奨される設定値の一括設定を行う機能との2つの機能を有する情報処理装置において、当該2つの機能の競合を考慮したセキュリティ関連機能を提供することができる。
Smart Images

Figure 0007898986000004 
Figure 0007898986000005 
Figure 0007898986000006
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus for collectively setting security-related functions.
Background Art
[0002] There is known a security policy function for setting a security policy in an information processing apparatus in accordance with an organization's security policy. In the security policy function, set values corresponding to the set security policy are set in the information processing apparatus. Since the set values set by the security policy function are set values reflecting the organization's security policy, other users are prevented from changing the set values. Patent Document 1 discloses a technique for performing settings according to a security policy by a user inputting a security policy setting to an information processing apparatus.
[0003] In recent years, information processing apparatuses have come to be installed in various environments such as telecommuting and public spaces where a network and the information processing apparatuses on the network are shared by an unspecified number of people, and the required security settings have become complicated. Therefore, Patent Document 2 discloses a technique for collectively setting security-related functions of an image forming apparatus according to a security level specified by a user. With such a function, it is possible to collectively set set values recommended in the environment in which the information processing apparatus is used and the security level required in that environment in the information processing apparatus.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
Summary of the Invention
[0005] However, neither Patent Document 1 nor 2 envisions an information processing device having two different functions: a security policy function that sets setting values according to the security policy set on the information processing device, and a function that sets recommended setting values in bulk. In cases where an information processing device has these two functions, it is possible that the setting items set by each function will overlap, and it will be necessary to consider the conflict of which setting value from the two functions to set for the overlapping setting items.
[0006] The present invention aims to provide security-related functions that take into account the conflict between the two functions described above. [Means for solving the problem]
[0007] To achieve the above objective, the information processing device of the present invention associates a first security policy set in the information processing device with the security policy set in the information processing device. Multiple settings A first setting means for setting the information processing device, and a second setting means associated with one usage environment selected from among a plurality of usage environments. Multiple settings A second setting means for setting the information processing device, and a control means for performing control such that, when the security policy is set in the information processing device, one of the multiple usage environments is not selected. have ru. [Effects of the Invention]
[0008] According to the present invention, in an information processing device having two functions, a security policy function that sets setting values according to a security policy set on the information processing device, and a function that sets recommended setting values in bulk, it is possible to provide security-related functions that take into account the conflict between these two functions. [Brief explanation of the drawing]
[0009] [Figure 1]This diagram illustrates an example of the usage environment for an information processing device. [Figure 2] This flowchart shows an example of conditions for classifying the usage environment of information processing equipment. [Figure 3] This figure shows an example of the hardware configuration of the image forming apparatus 101. [Figure 4] This figure shows an example of the software configuration of the image forming apparatus 101. [Figure 5] This figure shows an example of a screen displayed on the operation unit 320 of the image forming apparatus 101 in the first embodiment. [Figure 6] This figure shows an example of a screen displayed in the web UI of the image forming apparatus 101 in the first embodiment. [Figure 7] This flowchart shows an example of the security policy setting process performed by the image forming apparatus 101. [Figure 8] This flowchart shows an example of a screen display process performed by the image forming apparatus 101 in the first embodiment. [Figure 9] This figure shows an example of a screen displayed on the operation unit 320 or web UI of the image forming apparatus 101 in the first embodiment. [Figure 10] This flowchart shows an example of a security setting process performed by the image forming apparatus 101 in the second embodiment. [Modes for carrying out the invention]
[0010] The following describes embodiments for carrying out the present invention with reference to the drawings. Note that the following embodiments are not intended to limit the invention as defined in the claims, and not all combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0011] <First Embodiment> Figure 1 is a diagram illustrating the usage environment of the information processing device in this embodiment.
[0012] Examples of the information processing apparatus in this embodiment, image forming apparatuses 101 to 104, are installed in different usage environments 111 to 114, respectively. The usage environments 111 to 114 illustrated in FIG. 1 correspond to the in-company intranet environment 211, the Internet direct connection environment 212, the Internet prohibited environment 213, and the home environment 214 in FIG. 2, respectively.
[0013] The usage environment 111 corresponding to the in-company intranet environment 211 is an environment in which the image forming apparatus 101 and the PC 121 are connected via the enterprise's LAN (Local Area Network) 131. A firewall 141 is installed at the boundary between the LAN 131 and the Internet 100. That is, the communication between each information processing apparatus in the in-company intranet environment 211 and the Internet 100 is monitored and protected by the firewall 141. Therefore, in the in-company intranet environment 211, threats such as access to each information processing apparatus by attackers from the Internet 100 are greatly reduced.
[0014] On the other hand, no firewall is installed in the usage environment 112 corresponding to the Internet direct connection environment 212. The Internet direct connection environment 212 is an environment in which the image forming apparatus 102 and the PC 122 are directly connected to the Internet 100 and communicate. Therefore, information processing apparatuses such as the image forming apparatus 102 and the PC 122 need to take countermeasures against threats such as access by attackers from the Internet 100 by using the personal firewall function in each information processing apparatus.
[0015] The usage environment 113 corresponding to the Internet prohibited environment 213 is a closed network environment isolated from different networks such as the Internet 100. Information processing apparatuses such as the image forming apparatus 103 and the PC 123 are connected via the LAN 133. In the Internet prohibited environment 213, network communication is possible only between each information processing apparatus installed on the LAN 133. Each information processing apparatus is not accessed by unspecified users on the Internet 100.
[0016] The usage environment 114 corresponding to the in-home environment 214 is an environment in which an image forming apparatus 104 and a PC 124 are connected via a home LAN 134. The LAN 134 is a private network configured by a home router 144, but there is no security measure by a strong firewall such as the in-company intranet environment 211. Therefore, information processing apparatuses installed in the in-home environment 214, similar to the Internet direct connection environment 212, need to take countermeasures against threats such as access by attackers from the Internet 100 by using a personal firewall function in each information processing apparatus and the like.
[0017] In the present embodiment, in addition to the usage environments 111 to 114, a public space environment and a high-security management environment (not shown) are assumed. The classification of these six usage environments will be described in detail with reference to FIG. 2.
[0018] In the present embodiment, the usage environments of information processing apparatuses are classified into six types, and appropriate security settings are provided for each classification. FIG. 2 is a flowchart showing the concept of classification when classifying and defining usage environments. Note that the following definitions of usage environments do not limit the present invention, and some or other usage environments exemplified in the present embodiment may be defined. For example, assuming installation within a company, usage environments may be classified for each industry such as finance and government offices.
[0019] S201 is a classification as to whether it is an environment that handles highly confidential information. It can be said that an environment that handles highly confidential information is an environment that needs to prioritize security measures. Hereinafter, in the present embodiment, this environment that needs to prioritize security measures is defined as a high-security information management environment 216.
[0020] In environments that do not handle highly confidential information, the classification of usage environments can be further subdivided. S202 is a classification based on whether or not the environment is access-controlled. This is an example of a classification based on whether or not unspecified users can physically access the information processing device, that is, whether or not users are restricted from entering the location where the information processing device is installed. Therefore, the classification condition of whether or not physical access is possible is not limited to this embodiment, and conditions other than access control may also be used as classification conditions. Furthermore, access control in this embodiment is not limited to an access control system using cards. For example, an environment in which only people belonging to the organization work during business hours, effectively limiting who can enter, and where the doors are locked outside of business hours, is also included in the category of an access-controlled environment.
[0021] When there is no access control, that is, when an unspecified number of users can physically access the information processing device, the usage environment is subdivided according to the classification conditions shown in S205. S205 is a classification based on whether or not an unspecified number of users share and use the network within the environment. In this embodiment, an environment in which an unspecified number of users share and use the network within the environment is defined as a public space environment 215. Furthermore, an environment in which an unspecified number of users do not share the network within the environment is defined as a home environment 214. In this embodiment, an environment in which an unspecified number of users do not share the network within the environment, such as a home environment 214, that is, an environment in which users can be identified, is defined as a private network environment.
[0022] The user environments classified as having access control in S202 are further subdivided according to the classification criteria shown in S203. S203 is a classification based on whether or not the information processing devices within the environment are connected to an external network such as the Internet. An environment that is not connected to an external network such as the Internet is defined as an Internet-prohibited environment 213. Note that an Internet-prohibited environment 213 that has access control and is based on a closed network is a private network environment.
[0023] If the information processing devices within the environment are connected to an external network such as the Internet, the usage environment is further subdivided according to the classification conditions shown in S204. S204 is a classification based on whether or not a firewall is installed. An environment with a firewall installed is defined as an internal intranet environment 211. An environment without a firewall is defined as an internet-direct connection environment 212. Note that an internal intranet environment 211, in which users can be restricted by a firewall, is a private network environment.
[0024] Next, we will explain the six usage environments mentioned above and the security measures that should be taken for each environment, using Table 1. Here, we will give seven examples of security measures.
[0025] [Table 1]
[0026] Encrypting communication paths is a security measure that prevents information leakage by encrypting the content of communications over a network. One example of a function that enables communication path encryption is TLS (Transport Layer Security). In environments connected to the internet, it is desirable to encrypt communication paths because there is a possibility of eavesdropping on communications by third parties. In other words, except in internet-restricted environments (213), it is recommended to encrypt communication paths.
[0027] Disabling legacy protocols is a security measure that prevents impersonation and information leakage by disabling functions that use insecure legacy communication protocols. An example of a legacy protocol is WINS (Windows Internet Name Service). Similar to encrypting communication paths, disabling legacy protocols is desirable in environments connected to external networks such as the internet. In other words, disabling legacy protocols is recommended except in internet-restricted environments (213).
[0028] A personal firewall is a firewall installed and used on an information processing device. Like a regular firewall, it monitors communication between the information processing device and external networks such as the internet. Examples of firewalls include IP filters and port number filters. An IP filter is a security measure that reads the destination and source information of communication packets and allows only pre-configured communication packets. This prevents unauthorized access and information leakage. A port number filter is a security measure that closes unused ports to prevent intrusion through ports. This prevents Denial of Service (DoS) cyberattacks that overload a system and exploit vulnerabilities. In environments connected to an external network and without a firewall installed, there is a possibility of information leakage and DoS attacks, so it is desirable to enable a personal firewall. In other words, except for internet-restricted environments 213 that are not connected to an external network and internal intranet environments 211 where a firewall is installed, enabling a personal firewall is recommended.
[0029] Strengthening authentication security involves measures to combat impersonation, such as prohibiting password caching or specifying a minimum password length. Except for internet-restricted environments 213 connected within isolated networks, there is a possibility of impersonation, making it desirable to strengthen authentication security.
[0030] Physical attack countermeasures are security measures that prevent information from being leaked physically. In image forming apparatuses 101 to 104, temporary data such as print jobs is generated on the hard disk. A complete erasure function is provided that automatically and completely erases the generated temporary data at the same time as the job is completed. The complete erasure function described above is an example of a physical attack countermeasure for image forming apparatuses 101 to 104. If this function is set, even if the hard disk is physically removed, the temporary data cannot be read. In home environments 214 and public space environments 215, where access control is not in place and physical access to the information processing device cannot be restricted, it is desirable to implement physical attack countermeasures. Furthermore, in highly confidential information management environments 216, where reducing the risk of information leakage is the top priority, it is also desirable to implement physical attack countermeasures.
[0031] The file sharing function allows users to share files over a network within an environment. In environments where unspecified users share the network, it is desirable to disable the file sharing function to prevent information leakage. In other words, it is recommended to disable the file sharing function except in private network environments where specific users share the network. As mentioned above, the private network environments in this embodiment are the company intranet environment 211, the internet-restricted environment 213, and the home-based environment 214. Therefore, it is recommended to disable the file sharing function in environments other than these: the internet-connected environment 212, the public space environment 215, and the highly confidential information management environment 216. An example of a setting related to the file sharing function is the SMB (Server Message Block) server setting.
[0032] Disabling an external storage device means, for example, configuring an information processing device so that a USB (Universal Serial Base) storage device cannot be used as an external storage device. In image forming apparatuses 101 to 104, the USB storage device is used as a storage location for scanned data. By disabling the external storage device, it is possible to prevent information from being written to the external storage device and thus prevent information leakage. It is also possible to prevent infection by computer viruses via USB storage devices and the resulting information leakage. The threat of information leakage via external storage devices such as USB is common to all usage environments. Therefore, it is desirable to disable them in all usage environments.
[0033] Table 2 shows the recommended settings and values for each usage environment, based on the security measures described above. For items where a setting is recommended, the recommended setting value is indicated, such as "On," "Off," or "Deny." When a user selects a usage environment on the screen shown in Figure 5(b) below, the recommended settings for the selected environment will be applied.
[0034] Image forming apparatuses 101 to 104, which are examples of information processing devices, have a wide variety of settings, including settings for security functions and other settings, and perform various controls according to the setting values corresponding to these settings. In this embodiment, the items targeted for batch setting of security functions are the 22 items shown in Table 2.
[0035] [Table 2]
[0036] LPD, RAW, WSD, and IPP are printing protocols used for communication between client devices and printers. Unlike other protocols, IPP is a more secure printing protocol because the protocol itself provides user authentication, access control, and encryption of communication data. Therefore, it is recommended to enable "IPP printing" in highly confidential information management environments requiring high security. Conversely, LPD, RAW, and WSD, which are less secure than IPP, are recommended to be turned off except in trusted environments such as company intranets or environments where the internet is prohibited.
[0037] SNMP is a protocol for monitoring and controlling communication devices on a network, allowing you to check things like the number of pages printed and error information from a PC. SNMPv1 determines the communication range using information called a community name, but since the community name is transmitted over the network in plain text, there is a risk of information leakage. Therefore, it is recommended to turn this setting "off" except in trusted environments such as a company intranet or environments where internet access is prohibited.
[0038] A dedicated port is used to configure and access printer information from printer drivers, etc. Turning the "Use dedicated port" option to "Off" will prevent the acquisition of printer information when using printer drivers, etc., over a network connection. In environments with direct internet access or in public spaces, it is recommended to turn this option "Off" due to the risk of information leakage. It is also recommended to turn this option "Off" in highly confidential information management environments requiring high security.
[0039] Automatic deletion of interrupted jobs is a function that automatically deletes print jobs that have been interrupted due to errors or other reasons. This prevents situations where interrupted print jobs resume after a period of time, leaving printed documents unattended, thereby reducing the risk of information leakage. This setting is recommended to be enabled in home environments without access control, public spaces, and high-security environments requiring the management of highly confidential information.
[0040] A transmission result report is a report used to confirm whether a message was successfully sent to the intended recipient. This setting determines whether or not to automatically print reports of transmission results, such as fax, email, I-fax transmissions, and saving to file servers or user boxes. Turning off the transmission result report prevents reports containing information such as the content of the transmission and transmission history from being left on the printer, thus reducing the risk of information leakage. It is recommended to turn it off in home environments without access control, public spaces, and highly confidential information management environments requiring high security.
[0041] Simple Login is a login method where users log in by clicking on the username displayed on the control panel, eliminating the need to manually enter the username. Simple Login allows users to set a PIN. This setting allows you to configure whether or not to require the use of this PIN. If a PIN is not used, users can easily log in by simply selecting the username displayed on the control panel, but this carries the risk of identity theft. Turning this setting "on" reduces the risk of identity theft. This setting is recommended in environments such as home offices without access control, public spaces, and highly confidential information management environments requiring high security.
[0042] The "Show job status before authentication" setting, assuming you are using the login service, allows you to configure whether or not to display a screen showing your job status before authentication. By turning this setting "off," you can prevent an unspecified number of people from seeing your job status, reducing the risk of information leakage. This setting is recommended to be "off" in home environments without access control, public spaces, and highly confidential information management environments requiring high security.
[0043] Job history is a record of the execution of print jobs, and includes information such as the username of the user who ordered the print job and the name of the printed document. Turning off the display of job history prevents an unspecified number of people from seeing information such as the document name and the username of the user who printed it, thereby reducing the risk of information leakage. This setting is recommended to be turned off in home environments without access control, public spaces, and highly confidential information management environments requiring high security.
[0044] The audit log function allows you to audit security events. For example, user authentication logs can be used to audit for unauthorized access to equipment or attempts to do so, and logs of equipment usage such as printing, document sending, and configuration changes can be used to audit for unauthorized use of equipment. Key operation logs are logs of key operations performed by the user, including, for example, key operation logs during login. By saving and analyzing these logs, it is possible to investigate how the printer was operated. By obtaining or saving audit logs and key operation logs, it is possible to prevent users from denying unauthorized access or misuse. Since the risk of denial exists in any environment, these settings are recommended in common across all six environments.
[0045] Although not listed in Table 2, it is also possible to add the following settings for highly sensitive information management environments requiring high security. For example, "Use Mopria," "Use AirPrint," "Use Remote UI," etc.
[0046] Furthermore, in a home environment, it is possible to add the following items. For example, items related to PJL (Printer Job Language) and Admin (Embedded Web Server) passwords, SNMPv1 / v2, and SNMPv3. For example, it is possible to control the system so that administrator passwords for PJL and EWS cannot be changed from devices to which the home environment's centralized settings have been applied. SNMP is a device management protocol that allows administrators to obtain and set configuration values for image forming machines and other image forming devices over the network. With SNMP, it is possible to freely change the configuration values of image forming device functions, and the necessary permissions for each setting can also be managed. To prevent general users working from home from changing settings after the configuration values that comply with the company's policy have been reflected, it is possible to control the system so that settings such as permissions related to the device management protocol cannot be changed in a home environment. It is also possible to add settings for checking and updating the firmware version. In addition, it is possible to add settings to select whether or not to restrict access to PJL commands, and settings for redirection to HTTPS.
[0047] Note that the settings are not limited to those shown in Table 2, as long as they are appropriate for each usage environment. For example, Table 2 assumes that personal firewall settings are unnecessary in the company intranet environment because a firewall is already installed. However, there may be cases where the office firewall and a personal firewall are used together. Given this background, it is possible to perform a batch configuration including personal firewall settings even in company intranet environments and environments where internet access is prohibited. The same applies to other settings.
[0048] Of the settings shown in Table 2, TLS settings and personal firewall settings are general network settings. On the other hand, settings related to printing protocols and the functions and device management of the image forming apparatus, such as displaying print job history, are settings specific to the image forming apparatus.
[0049] The information processing device according to the present invention has a function to set recommended settings suitable for the selected usage environment, using the above-mentioned definitions of environment classifications and recommended settings for security functions as examples. This function is called the batch setting function. Furthermore, the information processing device according to the present invention has a function to set a security policy in accordance with the organization's security policy and to set settings according to the set security policy. This function is called the security policy function. The security policy function will be described below.
[0050] Image forming apparatuses 101 to 104, which are examples of information processing devices, have security-related settings corresponding to security policies. Some of the items targeted for setting security functions corresponding to security policies in this embodiment are shown in Table 3.
[0051] [Table 3]
[0052] The user can configure security policies on the security policy settings screen 610, which displays multiple security policies as shown in Figure 6(b), by checking the security policies they wish to configure. When the OK button 612 is pressed, the settings corresponding to the security policies are set on the information processing device. Using the security policy function, the user can set settings on the information processing device in accordance with the security policies of their organization.
[0053] Security policies configured on an information processing device can be exported and applied to other information processing devices. Furthermore, security policies configured on other information processing devices can be imported and applied to the same device. Additionally, security policies edited using device management software can be imported and applied.
[0054] In this embodiment, security policy settings can only be performed by a select group of administrators with strong privileges among the administrators of the information processing device. On the other hand, the batch setting function can be used by other administrators.
[0055] Table 3 shows an example of security policies that can be set on the image forming apparatus 101. The first column shows the security policy displayed on screen 610. The second and third columns show the setting items and values corresponding to the security policy in the first column, respectively. For example, if a user sets the security policy to "Restrict LPD ports," "Use LPD printing" will be set to "Off" in order to restrict the printing protocol used. Also, for example, if a user sets the security policy to "Force recording of audit logs," "Acquire audit logs," "Display job history," "Acquire operation logs," and "Display user name for print jobs as login name" will be set to "On."
[0056] This concludes the explanation of the batch setting function, which sets recommended settings appropriate for the selected usage environment, and the security policy function, which sets settings associated with the configured security policy. Some of the setting items corresponding to the settings set in each function are common. In this embodiment, the 14 setting items shown at the top of Table 3, which is an example of the security policy function, are common to the batch setting function shown in Table 2. That is, the setting items from "TLS settings" on the first row to "Display job history" on the 14th row are also included in Table 2. Among these, the setting items other than "Use IPP printing" and "Display job history" have the same setting values in both functions. The setting value corresponding to the setting item "Use IPP printing" is "On" in the batch setting function and "Off" in the security policy function. Also, the setting value corresponding to the setting item "Display job history" is "Off" in the batch setting function and "On" in the security policy function. Furthermore, there are setting items that are only applicable to the batch setting function and setting items that are only applicable to the security policy function. For example, while the bulk configuration function includes settings related to IP address filtering, automatic deletion of interrupted jobs, and transmission result reports, these are not included in the security policy function. Furthermore, the settings listed in Table 3, from row 15 "Acquire operation logs" to row 24 "Restrict new destinations," which are included in the security policy function, are not included in the bulk configuration function.
[0057] Note that the settings items covered by the security policy function shown in Table 3 and the settings items covered by the batch setting function shown in Table 2 are examples only and are not limited to these. For example, settings items that are included only in the security policy function in this embodiment, such as "Acquire operation logs," may also be configured to be included in the batch setting function.
[0058] Here, we will explain in detail the settings items shown in Table 3 that were not explained in Table 2. "Acquire operation log" is an item that sets whether or not to record a log of user operations. "Display user name for print jobs as login name" is an item that sets whether or not to display the user name of print jobs printed via direct connection as the login name.
[0059] The "Wired / Wireless LAN Selection" setting allows you to choose between wired and wireless LAN interfaces. By selecting "Wired LAN" as the setting value, you can disable the use of wireless LAN.
[0060] By setting the "Show warning when using default password" option to "On," you can configure the system to display a warning message if the password set at the time of purchase of the image forming machine is used.
[0061] Turning "Use fax memory reception" or "Use I-fax memory reception" to "On" allows you to configure the system to save received documents to the image forming machine's storage location before printing them immediately.
[0062] The "Forced Retention" setting, when turned "on," prevents documents from being printed immediately when printed from a PC. This setting reduces the risk of printed documents being seen by others or mistakenly taken by others.
[0063] The "Print when saving from printer driver" setting allows you to configure whether or not to print one copy simultaneously when saving a file from the printer driver. Setting this item to "Off" will prevent simultaneous printing when saving a file from the printer driver.
[0064] The "Restrict New Destinations" setting, when turned "on," prevents users from specifying destinations by text input when sending faxes or scanned data, limiting transmissions to only destinations registered in the address book. The settings are divided into four categories: fax, email, iFax, and file, and each item can be set to either on or off.
[0065] This embodiment provides an image forming apparatus that prevents conflicts in settings when controlling setting items based on the environmental classification described above and setting items based on security policies.
[0066] The following provides a detailed explanation.
[0067] <Hardware configuration of the image forming apparatus 101> The hardware configuration of the image forming apparatus 101, which is an example of an information processing device in this embodiment, will be explained with reference to Figure 3. Although Figure 3 only describes the image forming apparatus 101, the image forming apparatuses 102 to 104, and the image forming apparatuses installed in public space environments and high-security information management environments (not shown), will have the same configuration as the image forming apparatus 101.
[0068] The image forming apparatus 101 includes a printer 330 that outputs electronic data to paper media and a scanner 340 that reads paper media and converts it into electronic data. In this embodiment, an image forming apparatus 101 with multiple functions is given as an example of an information processing device, but it is not limited to this. For example, it may be a single-function printer or scanner, a 3D printer or 3D scanner, or other device. It may also be a PC or other device managed in accordance with a security policy.
[0069] The control unit 310, including the CPU (Central Processing Unit) 311, controls the operation of the entire image forming apparatus 101. The ROM (Read Only Memory) 312 is used to store programs executed by the CPU 311. The CPU 311 reads the control programs stored in the ROM 312 and performs various controls of the image forming apparatus 101, such as read control and transmission control. The RAM (Random Access Memory) 313 is used as the main memory and temporary storage area of the CPU 311, such as the work area. The HDD (Hard Disk Drive) 314 is a storage device that stores image data, various programs, and various setting information. Other storage devices such as an SSD (Solid State Drive) may also be provided. In this way, the hardware such as the CPU 311, ROM 312, RAM 313, and HDD 314 constitute a so-called computer.
[0070] The operation unit interface 315 connects the operation unit 320 and the control unit 310. The operation unit 320 is equipped with a liquid crystal display with touch panel functionality and various hard keys. The operation unit 320 functions as a display unit that shows information to the user and as a reception unit that receives user instructions.
[0071] The printer interface 316 connects the printer 330 and the control unit 310. Image data to be printed by the printer 330 is transferred from the control unit 310 via the printer interface 316. The input image data is output to the recording medium by the printer 330. The scanner interface 317 connects the scanner 340 and the control unit 310. The scanner 340 reads a document placed on a document glass (not shown) and generates image data. The generated image data is input to the control unit 310 via the scanner interface 317.
[0072] A network cable is connected to the network interface 318, allowing it to communicate with external devices on the LAN 131. In this embodiment, it is assumed to be a wired communication interface, but it is not limited to this. For example, it may be a wireless communication interface. The network interface 318 of the image forming apparatus 101 is connected to the LAN 131, but the network to which it is connected will vary depending on the operating environment. For example, the image forming apparatus 102 is directly connected to the internet 100. The image forming apparatuses 103 and 104 are connected to LAN 133 and 134, respectively.
[0073] <Software configuration of the image forming apparatus 101> Next, the software configuration of the image forming apparatus 101, which is an example of an information processing apparatus in this embodiment, will be explained using Figure 4. Each part shown in Figure 4 is realized by the CPU 311 executing the program 400 corresponding to each part stored in the ROM 312.
[0074] The operation control unit 410 displays a user-facing screen on the operation unit 320. It also detects user actions and switches screens or updates displays based on the detection results.
[0075] The data storage unit 420 stores data in the HDD 314 and reads data from the HDD 314 in accordance with requests from other control units. The data storage unit 420 stores setting information for determining the operation of the image forming apparatus 101, as well as information related to the setting of security functions. Specifically, it stores a recommended setting value database 421, previous setting data 422, current operation setting data 423, and a policy setting value database 424.
[0076] The recommended settings database 421 is a database as shown in Table 2 above. That is, it is a database that associates combinations of security function settings and setting values suitable for the usage environment of the image forming apparatus 101 with multiple divided usage environments. Here, setting items refer to items such as TLS settings and WINS settings. Setting values are indicated as "On," "Off," "Deny," etc. in Table 2. Setting items in Table 2 that have a blank setting value and are shown with a diagonal line indicate that there is no recommended setting value. That is, the setting value for that setting item is not changed, and the setting value from before the setting change is carried over. In this embodiment, the recommended settings database 421 is defined in advance by the vendor of the image forming apparatus 101 and stored in the data storage unit 420.
[0077] The pre-change setting data 422 is data of combinations of setting items and setting values that were applied before the user selected an environment type on screen 510 in Figure 5, which will be described later. Here, the setting items stored in the pre-change setting data 422 are the setting items that correspond to the setting values that are changed by the selection of the environment type. That is, in this embodiment, for example, in the case where an internet-prohibited environment is selected, the setting items stored in the pre-change setting data 422 are "Use USB external storage device", "Acquire audit log", and "Save key operation log". The setting values that were applied before the environment selection, corresponding to these three setting items, are stored in the pre-change setting data 422. Basically, it is used to restore the setting values when, after the security setting control unit 430, which will be described later, performs a batch setting, problems arise such as the end user not being able to use the desired function in the operation settings after the batch setting. In this embodiment, the pre-change setting data 422 is stored when an environment type is selected for the first time in the image forming apparatus 101, or when an environment type is selected for the first time after the cancel button 512, which will be described later, is pressed. In other words, if the user selects environment types consecutively, the previous setting data 422 will not be updated.
[0078] The policy setting database 424 is a database of combinations of security function settings and their corresponding settings, associated with security policies. Table 3 shows an example. The policy setting database 424 is defined in advance by the vendor of the image forming apparatus 101 and stored in the data storage unit 420.
[0079] The current operation setting data 423 is data relating to the settings currently applied to the image forming apparatus 101. For example, it includes data on combinations of security function settings and their corresponding values. When the security function settings are changed by the security policy function or the batch setting function, or when a user individually changes the settings, the current operation setting data 423 is rewritten. Subsequently, when the image forming apparatus 101 is restarted, the rewritten current operation setting data 423 is read by the program, and the image forming apparatus operates with the applied settings.
[0080] Furthermore, the current operation setting data 423 also includes information indicating whether each security policy shown in the first column of Table 3 is set. When the user selects the OK button 612 on screen 610 (described later), information indicating that the policy selected at the time the OK button 612 was selected is stored in the current operation setting data 423, indicating that the policy is set. For policies that were not selected, information indicating that the policy is not set is stored in the current operation setting data 423. Also, when security policies are imported and set in the image forming apparatus 101, information indicating whether each policy is set is stored in the current operation setting data 423, based on the settings of the imported security policies.
[0081] Furthermore, the current operation setting data 423 also includes information regarding the operating environment of the image forming apparatus 101. By default, this information stores information indicating that no operating environment has been selected. When the user selects an environment type on the screen 510 (described later) and presses the execute button 511, the information is overwritten. The information indicating the environment type selected from the operating environment list button 511 is stored in the current operation setting data 423 as information indicating the operating environment of the image forming apparatus 101.
[0082] The security setting control unit 430 configures the security functions of the image forming apparatus 101 in accordance with user instructions detected by the operation control unit 410. When an environment type is selected on screen 510 and the execute button 512 is pressed, the setting values corresponding to the selected usage environment are set all at once on the image forming apparatus 101. This is called the batch setting function. In addition, it is possible for the user to individually input security function settings from individual setting screens (not shown). The security setting control unit 430 also sets the setting values individually entered by the user on the image forming apparatus 101. Note that the setting of security functions by the security policy function is performed by the security policy setting control unit 450, which will be described later.
[0083] The batch setting function in this embodiment is a function that allows the recommended settings for typical security functions defined by the vendor to be set all at once. The security policy function is a function that applies a security policy edited by the administrator and sets the settings corresponding to the security policy. With this function, it is prohibited to individually change the settings set based on the security policy. On the other hand, even if a user such as an administrator has performed batch settings using the batch setting function, they can change the settings of individual setting items again to different settings via an individual setting change screen (not shown) according to the actual usage situation.
[0084] The security policy setting control unit 450 sets the security policy for the image forming apparatus 101 in accordance with user instructions detected by the operation control unit 410. If one or more security policies are selected on screen 610 and the OK button 612 is pressed, the setting values associated with each selected security policy are set in the image forming apparatus 101. This is called the security policy function. As mentioned above, this function applies the security policy edited by the user and prevents the user from changing the settings for specific security setting items to settings that do not conform to the policy.
[0085] The web UI (User Interface) control unit 440 controls the settings screen displayed on an external information processing device such as a PC 121 via the network I / F 318. The user can refer to and change the settings of the image forming apparatus 101 using the settings screen on a web browser provided by the web UI control unit 440, as illustrated in Figure 6.
[0086] Next, the setting screens 500 and 510 displayed on the operation unit 320 of the image forming apparatus 101 will be explained with reference to Figure 5. While the setting screens 500 and 510 displayed on the operation unit 320 of the image forming apparatus 101 are described here, the system is not limited to these. For example, the web UI control unit 440 can be used to provide a web page similar to the setting screen 500 to the web browser of an external information processing device, and the system can be configured to perform setting operations via this web page. For example, an example of a screen displayed on such a web page, corresponding to Figure 5(a), is shown in Figure 6(a).
[0087] In Figure 5(a), the settings screen 500 is a screen displayed on the operation unit 320 by the operation control unit 410. The recommended security settings menu button 501 is a button that allows the user to transition to a settings screen for performing batch settings. By pressing the recommended security settings menu button 501, the user can display the settings screen 510 for performing batch settings.
[0088] In Figure 5(b), the settings screen 510 is a screen displayed on the operation unit 320 by the operation control unit 410. The usage environment list button 511 is a button for the user to select a usage environment. On the settings screen 510, the user selects a usage environment for the image forming apparatus 101 from the usage environment list button 511 and presses the execute button 513. In this embodiment, the user selects from the six usage environment options shown in Figure 2. The operation control unit 410 of the image forming apparatus 101 detects the user's operation and transmits information indicating the user's selection result to the security setting control unit 430. The security setting control unit 430 then collectively sets the security functions appropriate for the usage environment selected by the user, based on the information received from the operation control unit 410.
[0089] The Cancel Settings button 512 is a button that allows the user to cancel the batch settings of security functions after they have been set. The user selects the Cancel Settings button 512 and then presses the Execute button 513. The Operation Control Unit 410 detects the user's operation and sends information to the Security Settings Control Unit 430 indicating the user's instruction to cancel the settings. Upon receiving the information indicating the instruction to cancel the settings, the Security Settings Control Unit 430 cancels the batch settings of security functions and returns to the original settings. Specifically, it overwrites the corresponding setting items in the current operation setting data 423 with the pre-change setting data 422 stored in the data storage unit 420. After the user selects the operating environment and the batch settings of security functions are set, there is a possibility that problems may occur in the use of the image forming apparatus 101. In such cases, by providing the Cancel Settings button 512, it is possible to return to the state before the batch settings were set, and problems can be addressed immediately.
[0090] Next, the web UI setting screens 600 and 610 that the web UI control unit 440 provides to the web browser of an external information processing device will be described with reference to Figure 6. In this embodiment, the web UI setting screens 600 and 610 will be described, but the invention is not limited to these. For example, the setting screens may be displayed on the operation unit 320 of the image forming apparatus 101.
[0091] In Figure 6(a), the settings screen 600 is the web UI screen that the web UI control unit 440 provides to the web browser of an external information processing device.
[0092] The security policy settings menu button 601 is a button that transitions to the settings screen 610 for configuring security policies. By pressing the security policy settings menu button 601, the user can display the settings screen 610 and configure security policies. The settings screen 610 will be described in detail later using Figure 6(b).
[0093] The Recommended Security Settings menu button 602 is a button that allows the user to transition to the settings screen 610 for performing bulk settings. By pressing the Recommended Security Settings menu button 602, the user can display a settings screen (not shown) on the web UI that corresponds to the settings screen 510 for performing bulk settings.
[0094] In Figure 6(b), the settings screen 610 is the web UI screen that the web UI control unit 440 provides to the web browser of an external information processing device. The security policy list buttons 611 are a group of buttons for the user to select the security policy of the image forming apparatus 101. On the settings screen 610, the user selects the security policy of the image forming apparatus 101 from the security policy list buttons 611 and presses the OK button 612. In this embodiment, the user selects from the security policy setting items shown in Table 3. The operation control unit 410 of the image forming apparatus 101 detects the user's operation and transmits information indicating the user's selection result to the security policy setting control unit 450. The security policy setting control unit 450 sets security functions appropriate to the security policy selected by the user, as received from the operation control unit 410, and restricts the functions that can be used by the image forming apparatus 101.
[0095] Next, Figure 7 will explain the process from when the user selects a security policy on screen 610 until the security policy is configured.
[0096] Each operation (step) shown in the flowchart of Figure 7 is realized by the CPU 311 calling a program stored in the ROM 312 or HDD 314 from the RAM 313 to implement the respective control unit and executing it.
[0097] When the security policy setting control unit 450 provides the setting screen 610 to the web browser of the external device PC 121 via the web UI control unit 440, the process shown in Figure 7 is initiated.
[0098] In S701, the security policy setting control unit 450 determines whether or not it has received a command to set a security policy. Specifically, first, the PC 121 displays the setting screen 610 provided by the security policy setting control unit 450 on its web browser and accepts user input. When the user performs an operation on the setting screen 610, the PC 121 accepts the operation. When the PC 121 receives confirmation that the user has selected a security policy and pressed the OK button 612, the PC 121 sends information to the image forming apparatus 101 indicating whether or not each security policy has been selected. The image forming apparatus 101 stores the received information in the current operation setting data 423 of the data storage unit 420. If one or more security policies have been selected, the image forming apparatus 101 determines that it has received a command to set a security policy. If it determines that it has received a command to set a security policy, it proceeds to S702; if it determines that it has not received one, it repeats S701 while waiting for reception. Furthermore, instead of being configured on screen 610, it may be determined that a command to set a security policy has been received when a security policy distributed from another image forming apparatus or device management software is imported. Similarly, when a security policy is imported, the settings of the imported security policy are saved in the data storage unit 420.
[0099] In S702, the security policy setting control unit 450 configures security-related items according to the received security policy settings. The security policy setting control unit 450 configures the settings by writing the setting items and values stored in the policy setting database 424 to the current operation setting data 423. Specifically, it refers to the information received from PC 121 in S701 and extracts the selected security policy. Then, it refers to the policy setting database 424 and extracts the setting items and values associated with the selected security policy. It changes the value of the setting corresponding to the extracted setting item stored in the current operation setting data 423 to the setting value from the extracted policy setting database. As a result, the setting values according to the security policy selected on screen 610 are set in the image forming apparatus 101. Furthermore, display control is performed to prevent the user from changing the state to which the use of functions restricted by this setting is enabled. Specifically, control is performed to prevent the user from individually changing the setting values of the setting items corresponding to the selected security policy on the setting screen displayed on the operation unit 320 of the image forming apparatus 101 and on the setting screen of the web UI. Furthermore, if the security policy setting received by the security policy setting control unit 450 is a command indicating the deactivation of a security policy, the following control is performed: The settings screen displayed on the operation unit 320 of the image forming apparatus 101 and the settings screen of the web UI are controlled to allow the user to individually change the setting values of the setting items corresponding to the relevant policy.
[0100] Although this embodiment was described using operations from a web UI, other embodiments may also be used, such as those using a settings screen displayed on the operation unit 320.
[0101] Through the above process, the user can configure security-related items for the image forming apparatus 101 according to the security policy settings.
[0102] Next, we will explain, using Figure 8, the process of determining whether security policy settings are configured and displaying the batch settings screen, taking into account conflicting behavior when security policies are applied.
[0103] Each operation (step) shown in the flowchart of Figure 8 is realized by the CPU 311 calling a program stored in the ROM 312 or HDD 314 from the RAM 313 to implement the respective control unit and executing it.
[0104] When the image forming apparatus 101 is started and the operation control unit 401 is ready to receive a command to display the setting screen 500 on the operation unit 320, or a command to provide the setting screen 600 via the web UI control unit, the process shown in Figure 8 begins. In this embodiment, the example described is one in which the operation control unit 401 receives a command to display the setting screen 500 on the operation unit 320, but other embodiments, such as receiving a command to provide the setting screen 600 via the web UI control unit 440, may also be used.
[0105] In S801, the operation control unit 401 determines whether it has received a command to display the setting screen 500 on the operation unit 320. If the operation control unit 401 has received a command to display the setting screen 500, it proceeds to S802. Specifically, the command to display the setting screen 500 is the pressing of a button to display the setting screen 500 on another screen (not shown) displayed on the operation unit 320. When the operation control unit 401 detects that the button has been pressed, it determines that it has received a command to display the setting screen 500. In the case where the setting screen 600 is displayed on the web browser of the PC 121 via the web UI control unit 440, S801 is performed by the web UI control unit 440. First, the PC 121 detects that a button to display the setting screen 600 has been pressed on another screen (not shown) displayed on the web browser. Then, the web UI control unit 440 of the image forming apparatus 101 receives information indicating this as a command to display the setting screen.
[0106] In S802, the operation control unit 401 reads setting information from the current operation setting data 423 and determines whether a security policy is set. The setting information read here is information stored in the current operation setting data 423 indicating whether each security policy is set or not. Based on this information, it is determined whether one or more security policies are set or not. If it is determined that one or more security policies are set, it is determined that a security policy is set. If no security policy is set, it is determined that no security policy is set. If a security policy is set, the process proceeds to S803. On the other hand, if no security policy is set, the process proceeds to S804.
[0107] In S803, the operation control unit 401, because a security policy has been set, changes the state of the recommended security settings menu button 511 to a state where the user cannot use it in order to restrict the use of batch settings. To achieve this state where the user cannot use it, in this embodiment, the recommended security settings menu button 501 is shaded to make it unresponsive to user input. That is, in S803, the operation control unit 401 performs the process of graying out the button 501 so that it cannot be pressed, after which it will be displayed in gray in S804. Once the shading process for the security settings menu button 501 is complete, the process proceeds to S804.
[0108] In S804, the operation control unit 401 displays a settings screen that takes into account the conflict between security policy settings and batch settings. Specifically, if a security policy has been set in S802, the operation control unit 401 displays a security settings screen on the operation unit 320 with the button 501 shaded. An example of the screen is shown in Figure 9(a). If a security policy has not been set in S802, the operation unit 320 displays a settings screen 500 without shading. Note that the configuration of the settings screen that takes into account the conflict between security policy settings and batch settings is not limited to the configuration shown in Figure 9(a). In S804, the text "Recommended Security Settings" displayed on the button 501 may be grayed out to prevent the button 501 from being pressed. Alternatively, an embodiment may be configured to show a screen that does not display the Recommended Security Settings menu button 501. In S803, processing should be performed to display a settings screen that takes into account the conflict between security policy settings and batch settings in S804.
[0109] Through the above process, a settings screen can be presented to the user that takes into account the conflict between security policy settings and batch settings, depending on the security policy settings for the image forming apparatus 101.
[0110] Next, we will explain the settings screen when a security policy has been set, using Figures 900 and 910.
[0111] In Figure 9(a), the settings screen 900 is an example of a settings screen that is displayed when considering conflicting behavior when a security policy is set for the settings screen 500. In other words, it is the settings screen that is displayed when the recommended security settings menu button 511 is shaded in S803 of Figure 8.
[0112] By shading the recommended security settings menu button 501, the command to display the settings screen 510 is prevented, thereby disabling the batch settings function if a security policy that should take priority has already been configured.
[0113] In Figure 9(b), the settings screen 910 is an example of a settings screen that is displayed when considering conflicting behavior in the case where a security policy is set for the settings screen 600.
[0114] On the settings screen 910, the recommended security settings menu button 602 is hidden, and the bulk settings screen cannot be displayed.
[0115] Through the series of processes described above, in an image forming apparatus where the highest priority security policy is set when configuring security-related items, a settings screen that takes into account conflicts between functions for configuring security-related items can be presented. In this way, users can use the system with a clear understanding of the relationships between multiple security-related item setting functions.
[0116] <Second Embodiment> In the first embodiment, when the security policy is set in the flow shown in Figure 7, the state of whether or not the setting has been done by batch setting is not taken into consideration, and the setting value according to the received security policy setting is set in the image forming apparatus 101.
[0117] On the other hand, when setting a security policy after the image forming apparatus 101 has already been configured using batch settings, the following challenges arise. One is that the user cannot determine which control takes precedence over the settings of security-related items controlled by both batch settings and security policy-based settings. Also, as mentioned above, the administrators who can set security policies are a select group of administrators with stronger privileges than the administrators who can use the batch settings function. Consider the case where recommended settings have been set using the batch settings function before the security policy is set. In this case, for setting items that are not included in the policy setting value database 424 but are included in the recommended setting value database 421, there is a possibility that other administrators may have set settings that were not anticipated by the security policy administrator by using the batch settings function.
[0118] Therefore, in this embodiment, the security policy setting process, which takes into account the case where a security policy is set after the settings have already been made by batch setting, will be explained using Figure 10. Note that the hardware configuration, software configuration, and setting screen configuration of the image forming apparatus 101 according to this embodiment are the same as in the first embodiment, so the explanation will be omitted. Also, the flow shown in Figure 8 will be performed in the same way as in the first embodiment. The flow shown in Figure 10 will be performed in place of the flow explained using Figure 7 in the first embodiment.
[0119] Each operation (step) shown in the flowchart of Figure 10 is realized by the CPU 311 calling a program stored in the ROM 312 or HDD 314 from the RAM 313 to implement the respective control unit and executing it.
[0120] When the security policy setting control unit 450 provides the setting screen 610 to the web browser of an external terminal via the web UI control unit 440, the process shown in Figure 10 is initiated.
[0121] In S1001, the security policy setting control unit 450 determines whether or not it has received a command to set a security policy. The specific processing is the same as in S701, so the explanation is omitted. If a command to set a security policy is received, the process proceeds to S1002; otherwise, S1001 is repeated while waiting for a command to be received.
[0122] Next, in S1002, the security policy setting control unit 450 determines whether or not the settings have already been configured via batch configuration. The security policy setting control unit 450 reads the settings for the usage environment selected by the usage environment list button 511 from the current operation settings 423. If the settings correspond to one of the six usage environments, it determines that batch configuration has been performed and proceeds to S1003. If no usage environment is configured, it proceeds to S1004.
[0123] In S1003, the security policy setting control unit 450 instructs the security setting control unit 430 to cancel the batch settings. The cancellation of the batch settings can be performed by the security setting control unit 430 overwriting the data of the setting values stored in the pre-change setting data 422 with the data of the corresponding setting values in the current operation setting data 423. Furthermore, the information regarding the usage environment selected for the image forming apparatus 101, which is stored in the current operation setting data 423, is also changed. Specifically, the security setting control unit 430 overwrites this information with information indicating that the usage environment for the image forming apparatus 101 is not selected. Once the cancellation process by the security setting control unit 430 is complete, the process proceeds to S1004.
[0124] In S1004, if security-related items have not been set using the batch setting function, the security policy setting control unit 450 sets the security-related items according to the received security policy setting. The security policy setting control unit 450 sets the items by writing the setting items and setting values stored in the policy setting database 424 to the current operation setting data 423. The specific process is the same as in S702, so the explanation is omitted. In addition, display control is performed to prevent the user from changing the state to which the use of the function restricted by this setting is enabled. Specifically, the settings screen displayed on the operation unit 320 of the image forming apparatus 101 and the setting screen of the web UI are controlled so that the setting values of the setting items corresponding to the selected security policy cannot be individually changed. If the security policy setting received by the security policy setting control unit 450 is a command indicating the deactivation of the security policy, the following control is performed: The settings screen displayed on the operation unit 320 of the image forming apparatus 101 and the setting screen of the web UI are controlled to a state where the user can individually change the setting values of the setting items corresponding to the relevant policy.
[0125] Similar to the first embodiment, this embodiment was described using operations from a web UI, but other embodiments may also be used, such as those using a settings screen displayed on the operation unit 320.
[0126] Through the above process, the user can configure security-related items in accordance with the security policy settings for the image forming apparatus 101, while taking into account any conflicts with batch settings.
[0127] Through the series of processes described above, the image forming apparatus 101 can perform security policy settings after deactivating the recommended settings that were set collectively according to the selection of the usage environment. Here, the security policy settings should be the highest priority setting among the security-related items in the image forming apparatus 101. This makes it possible to clarify which setting value is prioritized among the functions for setting security-related items. Furthermore, by deactivating the settings that were set by the collectively setting function before the administrator who can set the security policy can make the settings, it is possible to avoid situations where settings that were not anticipated by the security policy administrator are set. In addition, a setting screen that takes into account the conflicting operation of the security policy function and the collectively setting function can be presented. In this way, the user can use the system with the relationships between multiple security-related item setting functions clearly organized. [Explanation of symbols]
[0128] 101 Image forming apparatus 400 control programs 410 Operation Control Unit 420 Data Storage Unit 430 Security Settings Control Unit 440 Security Policy Setting Control Unit
Claims
1. An information processing device, A first setting means for setting a plurality of first setting values associated with a security policy set on the information processing device, A second setting means for setting a second set of settings associated with one usage environment selected from among multiple usage environments in the information processing device, When the security policy is set in the information processing device, control means that controls the selection of one of the multiple user environments so that no user environment is selected. An information processing device having
2. The information processing apparatus according to claim 1, characterized in that the first plurality of setting values and the second plurality of setting values include setting values corresponding to the same setting item.
3. The system includes a display control means that displays a button to be pressed in order to display a screen that accepts the selection of one usage environment from among the aforementioned multiple usage environments, The information processing apparatus according to claim 1, characterized in that the control means controls the button so that it cannot be pressed, as a control that prevents one of the multiple usage environments from being selected.
4. The information processing apparatus according to claim 3, characterized in that the control means controls the button so that one of the multiple usage environments is not selected, by graying out the text on the button and preventing the button from being pressed.
5. The information processing apparatus according to claim 3, characterized in that the control means controls the button not to be displayed as a control such that one of the multiple usage environments is not selected.
6. The information processing apparatus according to claim 1, characterized in that, when one usage environment is selected from the plurality of usage environments, the first setting means sets the setting value before the setting by the second setting means for the setting item corresponding to the second plurality of setting values, and then sets the first plurality of setting values.
7. The information processing apparatus according to claim 1, characterized in that the information processing apparatus is an image forming apparatus comprising at least one of a scanner and a printer.
8. The information processing apparatus according to claim 2, characterized in that the same setting item is a setting item relating to at least one of the scanner and printer provided by the information processing apparatus.
9. The information processing device according to claim 8, characterized in that the setting item relating to at least one of the scanner and printer provided by the information processing device is a setting item relating to the history recorded when a job is executed.
10. The information processing device according to claim 2, wherein the same setting item is a setting item relating to a scanner provided by the information processing device, and includes at least one of a setting item relating to the storage location of scanned data and a setting item relating to the history recorded when a job is executed.
11. The information processing device according to claim 2, wherein the same setting item is a setting item relating to a printer provided by the information processing device, and includes at least one of a setting item relating to restrictions on the protocol used for printing and a setting item relating to the history recorded when a job is executed.
12. A method for controlling an information processing device, A first setting step of setting a first set of multiple settings associated with a security policy set on the information processing device, A second setting step involves setting a second set of settings associated with one usage environment selected from among multiple usage environments in the information processing device, If the security policy is set in the information processing device, a control step is performed to ensure that one of the multiple user environments is not selected. A control method having
13. A program for causing a computer to execute the control method described in claim 12.