Skip to content

MFDs must not allow scan to SMTP (email).

An XCCDF Rule

Description

The SMTP engines found on the MFDs reviewed when writing the MFD STIG did not have robust enough security features supporting scan to email. Because of the lack of robust security, scan to email will be disabled on MFD devices. Failure to disable this feature could lead to an untraceable and possibly undetectable compromise of sensitive data. The SA will ensure MFDs do not allow scan to SMTP.

Property Value
Responsibility System Administrator

ID
SV-7029r2_rule
Version
MFD07.005
Severity
Medium
Updated

Remediation Templates

A Manual Procedure

Disable the scan to SMTP (email) feature on all MFDs.