Multifunction Device and Network Printers STIG
Rules, Groups, and Values defined within the XCCDF Benchmark
-
A MFD or printer is not configured to restrict jobs to those from print spoolers.
If MFDs or printers are not restricted to accept print jobs only from print spoolers that authenticate the user and log the job, a denial of service can be created by the MFD or printer accepting o...Rule Medium Severity -
MFD Authorized Users Restrictions
Group -
Print spoolers are not configured to restrict access to authorized users and restrict users to managing their own individual jobs.
If unauthorized users are allowed access to the print spooler they can queue large print file creating a denial of service for other users. If users are not restricted to manipulating only files t...Rule Medium Severity -
MFD and Spooler Auditing
Group -
The devices and their spoolers do not have auditing enabled.
Without auditing the identification and prosecution of an individual that performs malicious actions is difficult if not impossible.Rule Medium Severity -
MFD/Printer Security Policy
Group -
MFD Level of Audit and Reviewing
Group -
MFD Classified Network
Group -
MFDs with print, copy, scan, or fax capabilities must be prohibited on classified networks without the approval of the DAA.
MFDs with print, copy, scan, or fax capabilities, if compromised, could lead to the compromise of classified data or the compromise of the network. The IAO will ensure MFDs with copy, scan, or fax...Rule High Severity -
MFD Clearing Disk Space Scan to Disk
Group -
A MFD device, with scan to hard disk functionality used, is not configured to clear the hard disk between jobs.
If the MFD is compromised the un-cleared, previously used, space on the hard disk drive can be read which can lead to a compromise of sensitive data. The SA will ensure the device is configured to ...Rule Medium Severity -
MFD Scan Discretionary Access Control
Group -
Scan to a file share is enabled but the file shares do not have the appropriate discretionary access control list in place.
Without appropriate discretionary access controls unauthorized individuals may read the scanned data. This can lead to a compromise of sensitive data. The SA will ensure file shares have the appro...Rule Low Severity -
MFD fax from network auditing
Group -
Auditing of user access and fax logs must be enabled when fax from the network is enabled.
Without auditing the originator and destination of a fax cannot be determined. Prosecuting of an individual who maliciously compromises sensitive data via a fax will be hindered without audits. Th...Rule Low Severity -
MFD scan to SMTP (email)
Group -
MFDs must not allow scan to SMTP (email).
The SMTP engines found on the MFDs reviewed when writing the MFD STIG did not have robust enough security features supporting scan to email. Because of the lack of robust security, scan to email wi...Rule Medium Severity -
MFD Hard Drive Lock
Group -
A MFD device does not have a mechanism to lock and prevent access to the hard drive.
If the hard disk drive of a MFD can be removed from the MFD the data on the drive can be recovered and read. This can lead to a compromise of sensitive data. The IAO will ensure the device has a ...Rule Medium Severity -
MFD/Printer Global Configuration Settings
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.