5.1-4: MC Where a user can (8) authenticate against a device, the device shall provide to the user or an administrator a simple mechanism to change the authentication value used. 5.1-5: MC When the device is not a (5) constrained device, it shall have a mechanism available which makes bruteforce attacks on authentication mechanisms via network interfaces impracticable. MC (8) MC (8) MC (8) MC (5) MC (5) MC (5) and usage scenario, and the best practice cryptography that were referenced (if used). Supporting evidence shall show the password reset/change mechanism(s) that the consumer may use to change the authentication value. Supporting evidence shall describe the employed authentication rate limiting policy for making brute force attacks impracticable on each of the device's login-interfaces. Examples of login-interfaces not limited to the following: • • • Device and/or device management portal login; Companion Mobile Application login; Other network interfaces, ports or services. For each of the login-interfaces available on the device, supporting evidence shall describe the following: CLS Publication #2 | Page 24 of 49

Select target paragraph3