Attachment 2 - Printer and Multifunction Devices Secure Configuration Baseline.pdf

PDF 1 MB Posted

Attached to
W074--Copier Lease with Maintenance Federal contract opportunity
Solicitation number
36C10E23Q0028
Issued by
Department of Veterans Affairs Veteran Benefits Administration Headquarters

View the file

Other files for this federal contract opportunity

Other files attached to W074--Copier Lease with Maintenance, newest first.
File Type Posted
36C10E23Q0028 0001.docx DOCX document
Attachment 1 - General invoicing instructions.pdf PDF
36C10E23Q0028.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Printer and Multifunction Device Secure Configuration Baseline | i

Solution Delivery Security Engineering

Printer and Multifunction Device Secure Configuration Baseline Version 1.7

July 15, 2022 | IT Operations and Services

For Internal Use Only

Attachment - 2

Printer and Multifunction Device Secure Configuration Baseline | ii

OFFICE OF INFORMATION AND TECHNOLOGY

IT Operations and Services

Revision History

Date Reason for Changes Version Author

10/21/2014 Draft 0.1 Christopher Burdette

10/07/2015 Remove of Static or DHCP reserve statement as per VA POCs. Released version. SEDR15-1418

1.0 Perry Powell

01/09/2017 Modifications / update for Multifunction Device and Network Printer v2r8 STIG. SEDR17-1711

1.1 Perry Powell

05/16/2019 Rework of baseline for Solution Delivery template and baseline SOP. Modifications for Multifunction Device and Network Printer v2r13

STIG

1.2 Perry Powell

07/10/2019 Corrected typos, Appendix A table template design. Corrected bullets. Updated TOC.

Removed draft watermark.

1.3 Dave Stroebel (Tech Writer)

08/5/2019 Provided web link to Multi-Function Controls Checklist

1.4a William Roberson

06/23/2020 Minor text changes as well as latest STIG update 1.4b John Millard

07/10/2020 Update to DHCP, SNMP recommendations 1.4c Kimberly Ocasek

11/03/2020 Completed tech writer review and revisions to ensure 508 compliance.

1.4d Dave Stroebel (Technical Writer)

12/22/2020 Added printer ports and protocols to baseline and completed tech writer review and revisions to ensure 508 compliance.

1.5 Dave Stroebel (Technical

Writer)

02/04/2021 Clarification of VLAN guidance 1.6 K Kearney

02/01/2022 Minor updates for mDNS and WS-Discovery guidance

1.7 K Kearney

07/08/22 Completed tech writer review and revisions to ensure 508 compliance.

1.7 Kimberly West (Technical

Writer)

Printer and Multifunction Device Secure Configuration Baseline | iii

Printer and Multifunction Device Secure Configuration Baseline | iv

Table of Contents

1 INTRODUCTION

1.1 Purpose

1.2 Authority

1.3 Background

1.4 Scope

2 CONFIGURATION SETTINGS

2.1 System Application/Versions

2.2 Operational Configuration

2.3 Printer and Multifunctional Devices Baseline Configuration Implementation Plan

3 SECURITY COMPLIANCE

4 COMPLIANCE MONITORING

APPENDIX A: ACRONYMS

APPENDIX B: REFERENCES

Figures

Figure 1: OIS Review Executive Summary

Tables Table 1: NIST Validated Checklist

Table 2: Acronyms

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 5

1 INTRODUCTION

1.1 Purpose

This document describes the content and functionality of Printer and Multifunction Device Secure Configuration Baseline. It will go into detail on security protocols and requirements to be implemented when using printers, and multifunction devices (MFDs) on or attached to the Veteran Affairs network.

1.2 Authority

The organization responsible for this secure configuration baseline are:

Department of Veterans Affairs (VA) Office of Information & Technology (OI&T)

The content and direction of this secure configuration baseline is consistent with the requirements of the following publications:

· VA Knowledge Service.

· VA Directive 6500, Managing Information Security Risk: VA Information Security Program.

· VA Handbook 6500, Risk Management Framework for VA Information Systems – Tier 3:

· VA Information Security Program.

· Applicable:

o National Institute of Standards and Technology (NIST) Guidance.

o Manufacturer administration manuals.

o Department of Defense (DoD) Cyber Exchange Security Technical Implementation Guides (STIGs).

· Additional guidance is from the Continuous Readiness in Information Security Program (CRISP) Standard Operating Procedure to Support Development of and Modifications to CRISP Configuration Baseline Standards.

· Secure Configuration Baseline Standard Operating Procedure (SOP).

1.3 Background

Printers and MFDs are often utilized to transmit financial information, operational information, personal health information (PHI); and personally, identifiable information (PII) for the VA. The data security of these network-connected devices is often overlooked, and they are an easy access point to the network for exploitation. Hackers routinely target these devices, as this information can lead to further security breaches and harm for patients if information is leaked.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 6

1.4 Scope

The scope of this document is to provide a secure configuration baseline for printers and MFDs that are being managed as an enterprise device/system within the VA. Included within this document are security requirements and baseline settings to assist in defining the systems baseline security posture. Use of this secure configuration baseline will ensure that the device functions as required, in order to support reliable consistent operations.

This secure configuration baseline applies to all printers and MFD that are attached to the VA network or a device on the VA network. This baseline is not vendor specific and must be followed to ensure the security of printers.

2 CONFIGURATION SETTINGS

This section establishes the minimum required configurations for printers and MFDs in the Department of Veterans Affairs network environment.

2.1 System Application/Versions

This section establishes applications that are currently utilized or soon to be utilized in the enterprise for centralized security management of network printers. Utilization of these security management applications should be coordinated through the Printer Security Management (PSM) team.

Printer Security Management Configuration Applications

· HP Web Jetadmin (HPWJA) o Hewlett Packard (HP) management web tool (server) is capable of configuration and firmware pushes to printers (implemented).

o This application requires a SQL Instance and one named database (HPWJA).

· Lexmark Markvision Enterprise (MVE) o Lexmark / Dell management web tool (server) is capable of configuration, firmware pushes to printers, produce scan/fax usage reports, print usage reports, toner levels reports, and error messaging of the printer (implemented).

o This application requires a SQL Instance and three named databases (FRAMEWORK, QUARTZ, and MONITOR).

· Ricoh Streamline NX (SLNX) o Ricoh management web tool (server) is capable of configuration, firmware pushes to printers, produce scan/fax usage reports, print usage reports, toner levels reports, and error messaging of the printer (licensed software - implemented).

o This application requires a SQL Instance and one named database (RICOH_SLNX).

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 7

· Xerox Centreware Web (CWW) o Xerox management web tool (server) is capable of configuration, firmware pushes to printers, produce scan/fax usage reports, print usage reports, toner levels reports, and error messaging of the printer (IIS served with multiple sites).

o This application requires a SQL Instance and one named database (XeroxDM_XXX where XXX = 3 three-digit site code).

· ZebraNet Bridge Enterprise (ZNB) (Legacy) o Zebra desktop management tool is capable of configuration, firmware pushes, and error messaging of the printer (licensed software).

o Application is served only by desktop operation.

· Zebra Printer Profile Manager Enterprise (PPME) (Link OS) – Zebra desktop management tool (server) is capable of configuration, firmware pushes, and error messaging of the printer (licensed software).

Vendors are not allowed to be an administrator in any print management application implemented on the Veteran Affairs network. Vendors may be given access to specific site’s printers inside the management applications based on contracts in place and need.

Rights inside the application are to be implemented by least privilege.

Secure Print Applications

· Nuance Autostore/Output Manager o Secure print, scan, and follow me print solution that tracks usage of devices and utilizes rule-based printing.

o Requires printer to be reauthenticated to the software if the printer’s password is changed (licensed software).

o Nuance was acquired by Kofax in 2018.

· Lexmark Document Distributor (LDD) – Secure print solution that uses a frontend (web site) called Lexmark Management Console and backend Microsoft SQL Server (licensed software – replaced by LPM).

· Lexmark Print Management (LPM) On-Premises o Secure print and document accounting solution.

o Users send print jobs to a single print queue and jobs are released through user authentication at an enabled device.

Vendor Reporting

Printers are not allowed to directly communicate with servers / devices that are external of the Veteran Affairs network. Printers may communicate with an internal VA server and the information relayed externally if the server connection has been documented and approved as an external connection (requires Enterprise Security External Change Council (ESECC) approval).

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 8

· Lexmark Data Collection Manager – Server application that reports usage of printer (print, scan, fax, etc.), toner, and issues with Lexmark printers.

· Xerox Device Agent – Desktop application that reports usage of printer (print, scan, fax, etc.), toner, and issues with Xerox printers with eSolutions once registered.

· Ricoh @Remote o Reports usage of printer (print, scan, fax, etc.), toner, and issues with Ricoh printers.

o The application will automatically forward information to the datacenter in the event of a breakdown or other problem.

Veteran Affairs Reporting

· Printer Security Management (PSM) Integrated Database o Compilation of background database information for all printer security management applications implemented by the EPSM team - HP, Lexmark, Ricoh, Xerox, Zebra (as of July 2020).

o The solution is used to provide enterprise printer security configuration information, inventory reports, firmware reports, and other reports as required (This database is under development and not yet available for production use, as of July 2020).

o ForeScout CounterACT – Hardware/software that provides a comprehensive view of physical and virtual devices that are attached to the VA network.

· Information Central Analytics and Metrics (ICAMP) – This database is designed to store information from multiple sources in a central repository. Inputs are used to provide various data that includes vulnerabilities, Nessus data, and various formats as needed.

Print Servers

· Windows Server – Print and Document services role provides printer IP/hostname mapping, print queue information, device usage, user activity, document scanning, and error reporting.

· IBM/Red Hat Server – Print service utilized for patient billing and VCS that operates on

LPD.

· Fiery Command Workstation o Application that interacts with printers with the attached Fiery hardware (server).

o Software can hold print jobs and reassigning them to be associated with specific printers).

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 9

Applications for Veteran Management

· BOSS system o Burial Operations Support System prints application reports from the record keeping burial operation support system, which is used by the national cemetery administration users.

o After a printer is added for BOSS output, a ticket must be put into Application Support (IO.HBMC.FF.MEMORIAL.MEMAPPS) to request the output to that printer.

· Veterans Health Information System Technology Architecture (VistA) – VA’s current primary electronic health records management system.

· Computerized Patient Record System (CPRS) – Application used for management of patient information throughout the VA, driven by VistA.

· Electronic Health Records Management (EHRM) o Program implementation (led by Cerner) to securely digitize and manage patient records at an enterprise level (Expected to replace VistA once fully implemented.

Pilot implementation in progress).

o Specific hardware/software compatibility requirements are available.

· Biomed third-party apps – Used for printing EKGs and other information from systems such as GE and Siemens.

· BioPoint software – Utilized to print color patient wrist bands.

2.2 Operational Configuration

The following section establishes various configuration or additional requirements required for printers.

Non-security guidance

· Hostname of printers must be in accordance with: VA Naming Convention Knowledge Base

· The EHRM implementation will require printers and MFDs to be compatible with additional functionality and meet published minimum capabilities.

· New printer procurement guidance available, as of April 2021: OEHRM Site Infrastructure and End User Device (EUD) Requirements

· Acquisitions of new printers should be coordinated with the VA Office of Strategic Procurement prior to purchase and acceptance to ensure devices meet security requirements and VA compatibility requirements.

· Ensure secure print devices utilize a main and secondary domain controller, if possible, to prevent loss of functionality during domain controller maintenance.

https://dvagov.sharepoint.com/sites/NamingConventions/Pages/NamingConventionsKB.aspx https://dvagov.sharepoint.com/sites/NamingConventions/Pages/NamingConventionsKB.aspx https://dvagov.sharepoint.com/sites/VHAOCAMESEHRM/VHA Site Assessment Resources/Forms/AllItems.aspx?id=%2Fsites%2FVHAOCAMESEHRM%2FVHA%20Site%20Assessment%20Resources%2FPlanning%20Guides%20and%20Checklists%2F00%20VA%20OEHRM%20Site%20Infrastructure%20Requirements%20%2D%202%2E0%2Epdf&parent=%2Fsites%2FVHAOCAMESEHRM%2FVHA%20Site%20Assessment%20Resources%2FPlanning%20Guides%20and%20Checklists https://dvagov.sharepoint.com/sites/VHAOCAMESEHRM/VHA Site Assessment Resources/Forms/AllItems.aspx?id=%2Fsites%2FVHAOCAMESEHRM%2FVHA%20Site%20Assessment%20Resources%2FPlanning%20Guides%20and%20Checklists%2F00%20VA%20OEHRM%20Site%20Infrastructure%20Requirements%20%2D%202%2E0%2Epdf&parent=%2Fsites%2FVHAOCAMESEHRM%2FVHA%20Site%20Assessment%20Resources%2FPlanning%20Guides%20and%20Checklists

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 10

· Printers that are being decommissioned will have their hard drive removed and disposed of in accordance with VA Handbook 6500 guidelines and OIT OIS SOP Media Sanitization

SOP.

· Printers should be located on separate Virtual Local Area Networks (VLANs) than other devices.

· Encrypt the hard drive that is attached to the MFD.

· Ensure the Print from RAM option is enabled, if possible.

· Implement secure printing with passwords, smart cards, and/or biometric readers.

· If device has a timeout option, enable to ensure prints do not occur after the desired timeframe.

· Ensure that cached/stored print jobs are deleted after 24 hours if not retrieved. Business need exemptions can be made, if approved in writing by Printer Security Management team.

· Turn off the reprint command.

· Remediate any vulnerabilities found for the printer or MFD’s hardware, software, and operating system.

Additional hardware utilized with printers

Fiery EFI (Server) Device – Digital front end that is attached to or embedded in the printer (Required to function with the Fiery workstation application) Fiery print device and printer associated must both be restarted after configuration changes occur. Various Ethernet adapters–Multiple vendors produce ethernet cards that allow connection to a network. These ethernet cards stop ethernet connections to the actual printer and most have a web interfaces of their own. Even after changing a protocol in the adapter’s web interface, a vulnerability can be present due to the printer it is attached to. These adapters require local facilities to manage both the adapter and printer. They should not be utilized unless required for a vital VA function and cannot be replaced. Printers that must utilize these adapters should be replaced for printers that are compliant to the baseline and that can serve the same VA function when capable. Known vendors: Digiconnect, Edimax, Eltron, Epson, ExtendNet, Fastmark, Fastport, Gembird, Lantronix, Netgear, Netport, Roland, Scriptpro, Silex, TGNet, Troy, XCD.

3D Printer Guidance

At the time of this writing the Office of Information Security (OIS) is requiring all 3D printing technologies used within VHA to have a NISTIR 8023 Risk Assessment completed and approved by Cybersecurity Technology and Metrics (CTM). Please check the Printer and Multifunction Devices Page on the BCM Portal for vendor / model specific 3D printer Implementation Guides currently approved under Supporting Documents section. If you wish to add a printer not listed, please create a Service Now Request to start a security review and create a 3EPSMD printer Implementation Standard. These devices normally should not require an external vendor connection to support its operation however if it does, it will also require an approved Memorandum of Understanding/Interconnection Security Agreement (MOU/ISA) agreement.

https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/BCM/Lists/Secure_Configuration_Baselines/Item/displayifs.aspx?ID=45 https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/BCM/Lists/Secure_Configuration_Baselines/Item/displayifs.aspx?ID=45 https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/BCM/Lists/Secure_Configuration_Baselines/Item/displayifs.aspx?ID=45 https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/BCM/Lists/Secure_Configuration_Baselines/Item/displayifs.aspx?ID=45 https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/BCM/Lists/Secure_Configuration_Baselines/Item/displayifs.aspx?ID=45 https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/BCM/Lists/Secure_Configuration_Baselines/Item/displayifs.aspx?ID=45 https://yourit.va.gov/va?id=sc_cat_item&sys_id=4894aef0dbedc0949b1534cc7c961902 https://yourit.va.gov/va?id=sc_cat_item&sys_id=4894aef0dbedc0949b1534cc7c961902

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 11

Healthcare Technologies Management (HTM) has agreed to support these devices once approved.

2.3 Printer and Multifunctional Devices Baseline Configuration Implementation Plan

2.3.1 Implementation

This baseline can be implemented by the following personnel:

· OI&T

· Field Operations

2.3.2 Method

· The web interface of the printer.

· Some cases: management software, ssh, or a .profile upload.

· Obtain a copy of printer settings (vital settings)

· Ensure that latest firmware that does not introduce errors is on the printer or upload newest version provided by vendor’s website to remove vulnerabilities.

· Ensure barcode, label, wristband, plotter, and secure print printers (critical) are updated with their specific firmware only.

· Implement printer settings as necessary for individual printer models as followed:

(Ensure settings stay after reboot).

· Every printer will not have these settings. (Ports / protocols found on the printers should be set as defined below).

6110/6100 Port: Enable

Utilized by Lexmark Markvision to push security templates and firmware upgrades.

802.1x Authentication: Disable (Enable if utilized, ensure specific authentication protocols)

IEEE Standard for Port-based Network Access Control (PNAC). It is part of the IEEE 802.1 group of networking protocols. It provides an authentication mechanism to devices wishing to attach to a LAN or WLAN. The process involves three parties: requester, authenticator, and authentication server.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 12

9100 Printing: Enable

Port 9100

Also known as RAW printing. A type of TCP port in which data is passed unmodified to the receiving node. Setting allows any individual to print directly to the server by putting in the printer’s port number and bypass security. Required for VistA.

ACS: Enable

Protocol used to control and configure the machine setting via a PC application called Easy Printer Manager

Airprint: Disable

Port 80 and 5353

Mobile printing solution included with the Apple iOS v4.2 and later mobile operating systems.

IPad, iPhone, and iPod touch users can print wirelessly to any ePrint-enabled HP printer that is connected to the same local wireless network.

APIPA (Automatic Private IP Addressing): Disable

DHCP failover mechanism for local networks that generally is only useful on home or other small intranet LANs. APIPA allocates IP addresses in the private range 169.254.0.1 to

169.254.255.254. Clients verify their address is unique on the network using ARP. When the DHCP server is again able to service requests, clients update their addresses automatically. All devices use the default network mask 255.255.0.0 and reside on the same subnet. APIPA is enabled on all DHCP clients in windows unless the computer’s registry is modified to disable it.

APPLETALK: Disable

TCP/UDP Ports 201-208

Proprietary suite of networking protocols developed by Apple Inc. for their Macintosh computers. Includes a number of features that allowed local area networks to be connected with no prior setup or the need for a centralized router or server of any sort. Systems automatically assign addresses, update the distributed namespace, and configure any required inter-networking routing. Another form of printing that is not allowed due to STIG requirement to only print from 515 / 9100.

AutoIP: Disable

Protocol (on HP laserjet printers usually) that automatically pull a DHCP address for the network. This protocol can sometime be erroneous depending on the setup of the network.

Utilize DHCP protocol instead if pulling DHCP address for printers (suggest static IP addresses).

AVALANCHE: Disable

Allows remote display and modification to printer settings

Bluetooth: Disable

Unsecure wireless communications system intended to replace the cables connecting many types of devices.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 13

BOOTP (Bootstrap Protocol): Disable

Server UDP Port 67 / Client UDP Port 68

Protocol that lets a network client configure automatically. It can automatically configure any of the following information: IP address, gateway, subnet, system name, name server, and more.

It automatically assigns the necessary settings from a pool of pre-determined addresses for a certain duration of time. BOOTP is the basis for a more advanced network manager protocol, the DHCP (Dynamic Host Configuration Protocol).

Bonjour: Disable

UDP Port 5353

Apple's implementation of Zero-configuration networking (Zeroconf), a group of technologies that includes service discovery, address assignment, and hostname resolution. Bonjour locates devices such as printers, other computers, and the services that those devices offer on a local network using multicast Domain Name System (mDNS) service records.

BMLinks (Business Machine Linkage Service): Disable

Broadcast SAPs: Disable

HP OfficeJet Printers supporting PCL3 and PDL Language can use SAPWIN device type, which is a generic device type for printers linked (or also fax devices) to PCs running under MS Windows 3.1, Windows 95, Windows NT, Windows XP, Windows VistA, Windows 7 Operating System by means of the SAP System program SAPLPD. This protocol broadcasts the availability of utilizing

SAP.

CIFS (Common Internet File System): Enable

TCP / UDP Port 445 and TCP 139

Protocol that lets programs make requests for files and services on remote computers on the Internet. CIFS uses the client/server programming model and is a public or open variation of the Server Message Block Protocol (SMB) developed and used by Microsoft.

DHCP (Dynamic Host Configuration Protocol): Managed at site level

The site manages its IP space which includes employing DHCP, DHCP (reserved) and static on clients as needed.

Client TCP Port 67 / Server TCP Port 68

Alternative to another network IP management protocol, Bootstrap Protocol (BOOTP). Like BOOTP, DHCP can configure an IP address, gateway, subnet, system name, and name server.

BOOTP and DHCP configure the same options.

DHCPv4 FQDN compliance with RFC 4702: Disable

By default, HP Jetdirect uses the Host Name and Domain Name settings to derive the FQDN.

Selecting this option forces HP Jetdirect to ignore the Host Name and Domain Name settings and instead use the host name and domain name returned by FQDN.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 14

DIPRINT (Direct Printing Port): Enable

Port 9100

Enables direct printing from a network-connected computer. This is similar to port 9100 and RAW printing. Required for VistA.

Discovery: Disable

UDP Port 9200

DLC/LLC (Data Link Control / Logical Link Control): Disable

Older protocol used to print on Hewlett-Packard printers connected directly through networks.

The frames released are easily disassembled and DLC functionality can be easily coded into read-only memory (ROM). DLC doesn’t directly interface with Transport Driver Interface layer.

Only the print server communicating with the printer needs the DLC protocol installed.

DNS (Domain Name Server): Enable

Client to Server Lookup TCP/UDP Port 53

DNS Administration TCP 139

Protocol that maintains a directory of domain names and translate them to Internet Protocol (IP) addresses

DDNS (Dynamic DNS): Enable

Method of automatically updating a name server in the Domain Name System (DNS), often in real time, with the active DNS configuration of its configured hostnames, addresses or other information.

eCCL: Disable eFCL: Disable

Encryption Strength: Enable Strong, Disable weak

Only set the most secure settings for the printer. Ex. AES 256, SHA 512

Enhanced Print Port: Enable

TCP Port 9400

EPrint: Disable

TCP/UDP Port 5222

Uses cloud resources to provide mobile printing capabilities for specific HP ePrint-enabled printers and MFPs and for other printers using applications that provide network printing.

eSCL (AirPrint-Scan): Disable eSolutions: (Smart eSolutions) Disable (Enable if printer is required to report usage, toner, or supplies to a VA application server)

Feature that provides free services to enable administration of metered billing and supplies replenishment plans for printers on a network. This has to be configured with an application

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 15 server to hold the information and if sent outside the VA, a secure external connection has to be documented and approved.

Ethertalk: Disable

Port unknown

A suite of protocols developed by Apple for computer networking. It was included in the original Macintosh (1984) and is now deprecated by Apple in favor of TCP/IP networking.

Enables AppleTalk to communicate over Ethernet cabling.

Finger: Disable

TCP Port 79

Older (Windows 2000/NT) TCP/IP tool that matches an e-mail address with the person who owns it and provides information about that person.

FTP (File Transfer Protocol): Disable

Transfer TCP Port 20 / Control TCP Port 21

TCP/IP protocol and software that permits the transferring of files between computer systems.

FTPS (File Transfer Protocol Secure): Enable

TCP/UDP Port 989-990

Extension to File Transfer Protocol (FTP) that adds support for the Transport Layer Security (TLS) and the Secure Sockets Layer (SSL) cryptographic protocols.

Gleaning: Disable

Port Unknown

Older protocol that is a temporary, local configuration option. Gleaning lets you add the address of the device you want to configure to your local workstation’s ARP table. This configuration is not permanent and is valid only from the workstation from which you entered the ARP information. After the information is entered into the workstation’s ARP table, the user follows up with a Telnet session to enter the information permanently. This configuration option is used mostly by non-Windows workstations that cannot run the ZebraNet View configuration utility.

Google Cloud Print: Disable

HP XML Services: Enable

Enables or disables access by HP Web service applications to XML-based data on the HP Jetdirect print server. Utilized for print management security settings.

HTTP (Hypertext Transfer Protocol): Disable after HTTPS is interface for printer’s embedded web server (Leave enabled on Xerox devices, Ricoh secure print devices, and various printers that require http for https to work)

TCP Port 80

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 16

Application protocol for distributed, collaborative, hypermedia information systems. HTTP is used for communication between a web server and a web browser. Printers that require utilizing HTTP should have a redirect function to HTTPS.

HTTPS (Hypertext Transfer Protocol over SSL/TLS): Enable (Utilize TLS 1.0+ and disable SSL if capable)

TCP Port 443 / Dell OpenManage Port HTTPS TCP 1311

Protocol that uses SSL (Secure Sockets Layer) or TLS (Transport Layer Security) to encrypt communications on HTTP. For certificates for the printers: VA Enterprise Public Key Infrastructure (PKI)

IMAGE BUFFER: Disable

Intemec printers use this setting to save the last printed label in the web interface if unable to disable.

IMAP (Internet Message Access Protocol): Disable

TCP Port 143

IMAP SSL TCP Port 993

Protocol that interacts with a server to read, organize, reply to, search, and further interact with email. Standard IMAP procedure is to leave messages on the server instead of retrieving copies, so email is only accessible when "on-line."

IPDS (Intelligent Printer Data Stream): Disable

TCP Port 9600

Bidirectional communication protocol and object-oriented print stream between computer systems directly connecting with the print device.

IPP (Internet Printing Protocol): Disable

TCP/UDP Port 631

Internet protocol for communication between a print server and its clients. It allows clients to send print jobs to the server and perform administration such as querying the status of the printer and its print jobs and cancelling print jobs. IPPS is sometimes labeled as IPP with SSL / TLS communication as a configuration.

IPPS (Internet Printing Protocol Secure): Disable

TCP/UDP Port 443

Secure internet protocol for communication between a print server and its clients over SSL/TLS.

It allows clients to send print jobs to the server and perform administration such as querying the status of the printer and its print jobs and cancelling print jobs.

IPSEC: Disable (Enable if utilized)

Protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session. Requires certifying authority and keys.

http://vaww.pki.va.gov/ssltls/ http://vaww.pki.va.gov/ssltls/

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 17

IPV6: Disable

Addresses are represented as eight groups of four hexadecimal digits with the groups being separated by colons, for example 2001:0db8:0000:0042:0000:8a2e:0370:7334. It permits hierarchical address allocation methods that facilitate route aggregation across the Internet, and thus limit the expansion of routing tables. VA currently does not use IPV6.

IPX/SPX (Internetwork Packet Exchange/Sequenced Packet Exchange): Disable

Network connectionless routable network protocol based on the Xerox XNS architecture. IPX operates primarily at the Network layer of the OSI model and is responsible for addressing and routing packets to workstations or server on other networks. SPX operates at the Transport layer only.

IR (Intervention Required) Alerts: Disable

TCP Port 9200

Error data that is from the printer is received on port 9200. (Unidirectional)

JCP (Java Control Protocol): Disable (Ricoh’s Java/SDK is enabled for secure print)

Outdated java protocol used on older Sharp printers.

LDAP (Lightweight Directory Access Protocol): Disable (Enable if utilizing LDAP SSL)

TCP Port 389

LDAP SSL TCP Port 636

Open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network. A vulnerability was identified by Nessus with this protocol on printers.

LLMNR (Link-Local Multicast Name Resolution): Disable

UDP Port 5355

Protocol based on the Domain Name System (DNS) packet format that allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link.

LLTD (Link Layer Topology Discovery): Disable

Port unknown

Proprietary Link Layer protocol for network topology discovery and quality of service diagnostics. Microsoft developed it as part of the Windows Rally set of technologies.

LPR/LPD (Line Printer Remote / Line Printer Daemon): Enable

TCP Port 515

Network protocol for submitting print jobs to a remote printer or TCP/IP printer (PC fax send)

LPD Banner Page Printing: Disable

(IPv4 or IPv6) Print an LPD banner page for print jobs. For currently supported print servers, only Port 1 is available.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 18

LTP (Licklider Transmission Protocol): Enable

MaiLinX Remote Printing: Disable

Allows you to print to one or more Xerox printers over the internet, directly from Windows applications. The print jobs are sent as email (electronic mail).

MAPI (Messaging Application Programming Interface): Disable

TCP Port 135

Messaging architecture and a Component Object Model based API for Microsoft Windows.

Allows client programs to become (e-mail) messaging-enabled, -aware, or -based by calling MAPI subsystem routines that interface with certain messaging servers.

mDNS (Multicast Domain Name System): Disable (may be enabled for Lexmark or printer solutions that require mDNS for SNMPv3)

TCP/UDP Port 5353

Resolves host names to IP addresses within small networks that do not include a local name server. It is a zero-configuration service, using essentially the same programming interfaces, packet formats and operating semantics as the unicast Domain Name System (DNS). While it is designed to be stand-alone capable, it can work with unicast DNS servers. Has a vulnerability with protocol seen by Nessus.

Disable (Enable for OEM applications)

Resolves host names to IP addresses within small networks that do not include a local name server. It is a zero-configuration service, using essentially the same programming interfaces, packet formats and operating semantics as the unicast Domain Name System (DNS). While it is designed to be stand-alone capable, it can work with unicast DNS servers. Has a vulnerability with protocol seen by Nessus.

Mopria: Disable

Multicast IPV4: Disable

IPV4 multicasting is the sending of network traffic to IPV4 endpoints. Only those members in the group of endpoints that are listening for the multicast traffic (the multicast group) process the multicast traffic. All other nodes ignore the multicast traffic.

Multicast Discovery: Disable

NetBEUI/NETBIOS/IP (NetBIOS Extended User Interface / Network Basic Input /Output System / Internet Protocol): Enable

Lexmark Port TCP/ UDP 137

NetBIOS is the network Basic Input/Output System. In its most generic form, it is the application programming interface (API) that Microsoft originally used to allow Windows to utilize networking. The NetBIOS Extended User Interface (NetBEUI) expanded on this and is used to transport NetBIOS across a local area network (LAN). NetBEUI advantages are that it is easily

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 19 configured, has low overhead, and is configured for LANs. Disadvantages are that it is not routable and doesn’t handle large networks well.

Netware: Disable

Protocol that allows connection to shared printers on the dedicated server and print as if the printer were connected locally.

Network Scan: Enable

Allows scanning a document from the printer to your local computer.

Network TWAIN: Disable

Protocol that lets you scan an image (using a scanner) directly into the application (such as PhotoShop) where you want to work with the image.

NFS (Network File Sharing): Disable

Distributed file system protocol originally developed by Sun Microsystems in 1984 that allows a user on a client computer to access files over a network much like local storage is accessed. NFS builds on the Open Network Computing Remote Procedure Call (ONC RPC) system.

NTP (Network Time Protocol): Enable (Utilize ntp.va.gov or ntp1.va.gov)

UDP Port 123

Networking protocol for clock synchronization between computer systems over packetswitched, variable-latency data networks. If it is to be enabled, set the time server to a DOD approved NTP server (time.nist.gov).

NNTP (Network News Transfer Protocol): Disable

TCP Port 119

NNTP SSL TCP Port 563

Application protocol used for transporting Usenet news articles (netnews) between news servers and for reading and posting articles by end user client applications.

NPA (Network Printing Alliance): Enable 9300-9302 / 9500-9501

UDP Port 9300-9302 / TCP Port 9500-9501

Protocol for returning printer configuration and status via parallel, serial, network and later

USB. In 1997, NPAP was approved as IEEE 1284.1 TIPSI. However, SNMP became the standard for network printer management and thus NPAP was never widely accepted. Lexmark Markvision utilizes NPAP ports 9500-9501 for security template changes.

PCL SmartSwitch (Print Command Language Smartswitch): Enable (needed for VistA)

Sets the printer to automatically switch to PCL emulation when a print job requires it, regardless of the default printer language. When the “Off” setting is used, the printer does not examine incoming data.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 20

When the “off” setting is used, the printer uses PostScript emulation if PS SmartSwitch is set to “on”. It uses the default printer language specified in the Setup menu if PS SmartSwitch is set to “off”.

PCL Line Termination: Enable

Carriage-return after each linefeed to the PCL print settings for the BOSS system.

PJL (Printer Job Language): Disable

Method developed by Hewlett-Packard for switching printer languages at the job level, and for status read back between the printer and the host computer. PJL adds job level controls, such as printer language switching, job separation, environment, status read back, device attendance and file system commands. While PJL was conceived as an extension to Printer Command Language, it is now supported by most PostScript printers. A password can be configured to stop connections on most but not all printers.

PML (HP Printer Management Language): Disable

Protocol that allows many applications to exchange device management information with many printers. PML is an object-oriented request-reply protocol which supports asynchronous printer query, control, and monitor capabilities. Can be used to query SNMP values from a printer device.

Plug-n-Print: Disable

Allows the device to be capable of printing from USB and other removable devices.

POP3 (Post Office Protocol): Disable

TCP Port 110

POP3 SSL TCP Port 995

Protocol used to retrieve email from the mail server and be stored on the local computer. There is a setting to leave all messages there or delete them after mail is received and stored locally.

POSTSCRIPT: Enable

Computer language for creating vector graphics. It is a dynamically typed, concatenative programming language.

Print from RAM: Enable

Utilizes the printer’s ram instead of hard disk to perform printing, scanning, and faxing.

Printer Port Monitor MIB: Disable

Provides information from a printer to a host system to facilitate the automatic installation of device drivers and other printing applications. The information provided for each print service includes connectivity parameters (such as raw TCP printing sockets and LPR/LPD queue names), status monitoring capability, and printer model and manufacturer data. MIB broadcasts public

SNMP.

PrinterOn Cloud Print: Disable

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 21

PS SmartSwitch: Enable

Sets the printer to automatically switch to PS emulation when a print job requires it, regardless of the default printer language. When the “off” setting is used, the printer does not examine incoming data.

RARP (Reverse Address Resolution Protocol): Disable

Obsolete computer networking protocol used by a client computer to request its Internet Protocol (IPv4) address from a computer network, when all it has available is its Link Layer or hardware address, such as a MAC address.

RAW Port: Enable

TCP Port 9100

Also known as 9100 printing. A type of TCP port in which data is passed unmodified to the receiving node. Setting allows any individual to print directly to the server by putting in the printer’s port number and bypass security. Required for VistA.

RCFG (remote configuration protocol): Disable

Port 8001

Protocol developed by HP for remote configuration and management of devices on an IPX/SPX network, typically a Novell NetWare network. Mostly used for remote IP video cameras.

Remote Operator Panel: Disable (Enable only if utilizing and is a secure connection)

Reprint: Disable / Turn off

Option allows the reprinting of the last document.

RHPP (Reliable / Ricoh Host Printing Protocol): Disable

Port 59100

Older printing protocol created for Ricoh printers. No information on this protocol.

RSH (Remote Shell) / RCP (remote copy): Disable

TCP Port 514

RSH allows you to execute non-interactive programs on another system. On some systems, this command is sometimes called remsh or rcmd. It executes the command on the other system and returns the program’s standard output and standard error output.

RCP allows you to transfer files to and from another system over the network. It works like a “copy” command, where you specify a source and a destination, except that the source or destination of the copy can be the hostname or IP address of another system.

SETIP: Disable

Protocol that allows software to identify Samsung printers by MAC address and assign a printer IP address.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 22

SFTP: Enable

Network protocol used for secure file transfer over secure shell Secure file transfer program.

Show IP address: Disable

Setting shows the printer’s IP address on the printer’s control panel along with toner levels.

SSH (Secure Shell): Disable

Port 22

Encrypted network protocol that allows a user to run commands on a machine's command prompt without them being physically present near the machine. It also allows a user to establish a secure channel over an insecure network in a client-server architecture, connecting an SSH client application with an SSH server.

SLP (Service Location Protocol): Disable

UDP Port 427

Service discovery protocol that allows computers and other devices to find services in a local area network without prior configuration. SLP has been designed to scale from small, unmanaged networks to large enterprise networks.

SMARTSYSTEMS: Disable

SMB (Server Message Block): Disable (Enable if utilized by device)

TCP Port 445

Network file sharing protocol implemented by Microsoft. The set of message packets that defines a particular version of the protocol is called the dialect. Update firmware if SMB vulnerabilities are found.

SMTP (Simple Mail Transfer Protocol): Disable (Enable if utilized with PIV / encryption – Do not scan patient records to email)

TCP Port 25

A protocol used to send email messages over the Internet that can then be retrieved with an email client using either POP or IMAP protocols.

SMTPS (Simple Mail Transfer Protocol Secure): Enable

TCP Port 465

Method for securing SMTP with transport layer security. It is intended to provide authentication of the communication partners, as well as data integrity and confidentiality.

SMTPS is not a proprietary protocol and not an extension of SMTP. It is just a way to secure SMTP at the transport layer by SSL or TLS.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 23

SNMP V1&V2c (Simple Network Management Protocol): Disable (unless actively utilized)

UDP Port 161

A protocol for monitoring and controlling devices on a network. SNMP v1 and v2c only utilize a community string that is passed over clear text. Ensure this is set to district community name.

(Not public or private) (Update required from previous regional string).

SNMP V3 (Simple Network Management Protocol): Enable (unless V1 or V2 is required)

TCP Port 161

Protocol utilized for monitoring and controlling devices on a network. SNMPv3 utilizes a username, password, and encryption to the printer.

SNMP Traps: Disable (Enable only in cases needed for reporting leased / rented printers)

UDP Port 162

Enables an agent to notify the management station of significant events by way of an unsolicited SNMP message for error analysis. Includes current sysUpTime value, an OID identifying the type of trap and optional variable bindings. Destination addressing for traps is determined in an application-specific manner typically through trap configuration variables in the MIB. Ensure this is not set to public or private.

SNTP (Simple Network Time Protocol): Disable (Enable on Xerox printers that utilize secure print feature)

UDP Port 123

A less complex implementation of Network Time Protocol (NTP), using the same protocol but without requiring the storage of state over extended periods of time.

SOAP: Disable (Enable on Xerox printers that utilize secure print feature)

SSDP (Simple Service Discovery Protocol): Disable (Enable on Konica Minolta printers for Net Care Device Manager and Nuance Secure Print)

UDP Port 1900

A network protocol based on the Internet Protocol Suite for advertisement and discovery of network services and presence information that doesn’t utilize DHCP or DNS.

Walk-up Printing (USB): Disable

Tandem Output Receive: Disable

TCP 50001 / UDP 50001

Protocol used to run two Sharp machines off a single print driver.

Telnet: Disable

TCP Port 23 / Lexmark Telnet TCP 9000

Protocol that functions at the application layer of the OSI model, providing terminal emulation capabilities. Telnet uses the connection-oriented services of the TCP/IP protocol for

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 24 communications. With Telnet, the command to initiate the session is TELNET itself, or TELNET followed by an IP address or hostname to connect to a specific remote host. The remote host system must be running a telnet daemon or service, and after a connection is established, you must log on to the server by using a valid username and password (plain text) as if you were sitting at the server.

TFTP (Trivial File Transfer Protocol): Disable

UDP Port 69

Simple, lockstep, file transfer protocol which allows a client to get from or put a file onto a remote host. One of its primary uses is in the early stages of nodes booting in a Local Area Network (LAN).

ThinPrint: Disable

Protocol that allows print data to be compressed at the server and decompressed at the client before being printed out on a printer. Increased data transfer speeds resulting from the implementation of this protocol save time and money.

XML (Extensible Markup Language): Enable

TCP 5000

Allows the printer to be capable of importing / exporting security template information into an .xml format. Utilized for HP web Jetadmin and Markvision.

Web Services Print: Disable

Printer Service

Ability of printer to print while having protocol WSD enabled. Disabled due to STIG requirement of 515 / 9100 printing only.

WINS (Windows Internet Name Service): Disable

TCP Port 42

Protocol that centrally maps host names to network addresses. Like DNS, it is implemented in two parts, a server service (that manages the embedded Jet Database, server to server replication, service requests, and conflicts) and a TCP/IP client component which manages the client's registration and renewal of names and takes care of queries.

Wireless: Disable

Setting that allows the printer to act as an access point for computers to connect to it and print.

This is vulnerable to spoofing. A rogue system or drone can spoof this access point, intercept the data, and retransmit to another destination.

WS-Discovery (Web Services Dynamic Discovery): Disable (may be enabled when explicitly required by vendor printer management solution (e.g. HP, Lexmark, Xerox, and Ricoh)).

TCP/UDP Port 3702

Technical specification that defines a multicast discovery protocol to locate services on a local network. It uses IP multicast address 239.255.255.250.

July 2022 Printer and Multifunction Device Secure Configuration Baseline | 25

WSD (Web Services on Devices): Disable (Enable for OEM applications)

3 SECURITY COMPLIANCE

The Multifunction Device and Network Printers STIG provides the technical security policies, requirements, and implementation details for applying security concepts to the device.

Table 1: NIST Validated Checklist

STIG/SRG Requirement Version Date Testing Status Checklist

Multifunction Device and Network Printers STIG

Version 2 Release 14 October 25, 2019 Applied

MULTI-FUNCTION_D

EVICE-Controls Chec

Multi-function Device Controls Checklist

4 COMPLIANCE MONITORING

Compliance with the Multifunction Device and Network Printer STIG security control’s checklist is conducted manually or automatically based on the system reports described below.

· Manual check against the printer’s configuration setting, physical topology, and firmware version using the controls checklist (Required annually if not managed under application).

· Port and security configuration settings and firmware based on printer management applications implemented and the Centralized Printer Management Reporting Database.

· Nessus / ICAMP performs various scans (vulnerability, port, EDS Default password, EDS firmware, etc.) that can find ports open or various vulnerabilities with printers.

Printers that are found to be non-compliant devices (unable to be put to baseline for some reason) must be either utilized by USB port (in cases where there is no replacement for the printer and doesn’t pose risk by vulnerability) or removed completely from the network and replaced / disposed of in accordance with VA6500 handbook: RISK MANAGEMENT

FRAMEWORK FOR VA INFORMATION SYSTEMS VA INFORMATION SECURITY PROGRAM

https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/BCM/Lists/Secure_Configuration_Baselines/Item/displayifs.aspx?ID=45 https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/BCM/Lists/Secure_Configuration_Baselines/Item/displayifs.aspx?ID=45…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .