5.5-4: Access to device functionality via a network interface in the initialized state should only be possible after authentication on that interface. 5.5-5: Device functionality that allows security-relevant changes in configuration via a network interface shall only be accessible after authentication. The exception is for network service protocols that are relied upon by the device and where the manufacturer cannot guarantee what configuration will be required for the device to operate. R R R R R R R M used could be updated with a software update). Supporting evidence shall list all network interfaces on the device and the authentication mechanisms available on all of the network interfaces. In addition, if certain device functionalities are available prior to authentication, a description of the purpose for allowing those functionalities shall be provided. Supporting evidence shall describe that authentication is required prior to making security-relevant changes. Example scenarios: • • • Administrator's authentication is required prior to making changes in the device's web configuration portal. Administrator's authentication is required prior to configuring security-relevant changes to the device using the companion mobile application. Authentication should also be required for any other interfaces/methods that facilitates making security-relevant changes. CLS Publication #2 | Page 34 of 49

Select target paragraph3