STIGQter STIGQter: STIG Summary: Multifunction Device and Network Printers STIG Version: 2 Release: 14 Benchmark Date: 25 Oct 2019:

Implementation of an MFD and printer security policy for the protection of classified information.

DISA Rule

SV-7023r3_rule

Vulnerability Number

V-6798

Group Title

MFD/Printer Security Policy

Rule Version

MFD06.002

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Develop and implement an MFD and printer security policy consistent with DoDM 5200.01, Volume 3, Section 14.

Check Contents

Obtain and review the organization's MFD and printer security policy. If none is provided, this is a finding. If it does not prescribe the appropriate safeguards listed below, this is a finding.
Safeguards to be listed in the organization's MFD and printer security policy;
a. Prevent unauthorized access to that information, including by repair or maintenance personnel.
b. Ensure that repair procedures do not result in unauthorized dissemination of or access to classified information.
c. Replace and destroy equipment parts in the appropriate manner when classified information cannot be removed.
d. Ensure that appropriately knowledgeable, cleared personnel inspect equipment and associated media used to process classified information before the equipment is removed from protected areas to ensure there is no retained classified information.
e. Ensure MFD and printers used to process classified information are certified and accredited in accordance with DoDD 8500.01E.
f. Ensure that MFD and printers address issues concerning compromising emanations in accordance with DoDD 8500.01E.

Vulnerability Number

V-6798

Documentable

False

Rule Version

MFD06.002

Severity Override Guidance

Obtain and review the organization's MFD and printer security policy. If none is provided, this is a finding. If it does not prescribe the appropriate safeguards listed below, this is a finding.
Safeguards to be listed in the organization's MFD and printer security policy;
a. Prevent unauthorized access to that information, including by repair or maintenance personnel.
b. Ensure that repair procedures do not result in unauthorized dissemination of or access to classified information.
c. Replace and destroy equipment parts in the appropriate manner when classified information cannot be removed.
d. Ensure that appropriately knowledgeable, cleared personnel inspect equipment and associated media used to process classified information before the equipment is removed from protected areas to ensure there is no retained classified information.
e. Ensure MFD and printers used to process classified information are certified and accredited in accordance with DoDD 8500.01E.
f. Ensure that MFD and printers address issues concerning compromising emanations in accordance with DoDD 8500.01E.

Check Content Reference

I

Target Key

551

Comments