MFDs with print, copy, scan, or fax capabilities must be prohibited on classified networks without the approval of the DAA.
An XCCDF Rule
Description
<VulnDiscussion>MFDs with print, copy, scan, or fax capabilities, if compromised, could lead to the compromise of classified data or the compromise of the network. The IAO will ensure MFDs with copy, scan, or fax capabilities are not allowed on classified networks unless approved by the DAA.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts>If the device is removed from the classified network it will need to be sanitized in accordance with DoDD 5200.1R if it is to be used for unclassified processing or is to be decommissioned.</PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility>Information Assurance Officer</Responsibility><IAControls>DCBP-1</IAControls>
- ID
- SV-7025r2_rule
- Severity
- High
- Updated
Remediation - Manual Procedure
Remove the MFD from the classified network until DAA approval is obtained.