Amendment_1_SP7000-19-Q-0024_0001.pdf
PDF 2 MB Posted
- Attached to
- Small-Format Reproduction Equipment Federal contract opportunity
- Solicitation number
- SP7000-19-Q-0024
- Issued by
- Defense Logistics Agency
About this file
Amendment 1 SP7000-19-Q-0024 0001 Answer questions from prospective vendors.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_3_SP7000-19-Q-0024_0003.pdf | ||
| Amendment_2_SP7000-19-Q-0024_0002.pdf | ||
| SP7000-19-Q-0024_Combined_Synopsis_Solicitation.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
1. CONTRACT ID CODE
2. AMENDMENT/MODIFICATION NO.
4. REQUISITION/PURCHASE REQ. NO.
See Block 14
5. PROJECT NO. (If applicable)
6. ISSUED BY CODE SP7000 7. ADMINISTERED BY (If other than Item 6) CODE
8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)
CODE FACILITY CODE
SP700019Q0024
X
2019 JUL 03
10A. MODIFICATION OF CONTRACT/ORDER NO.
10B. DATED (SEE ITEM 13)
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of OffersX is extended, X is not extended.
or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted;
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:
12. ACCOUNTING AND APPROPRIATION DATA (If required)
A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO.
IN ITEM 10A.
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc. ) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
E. IMPORTANT: Contractor is not, is required to sign this document and return copies to issuing office.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A NAME AND TITLE OF SIGNER (Type or print)
NSN 7540-01-152-8070
Previous edition unusable
STANDARD FORM 30 (REV. 10-83)
Prescribed by GSA FAR (48 CFR) 53.243
16B. UNITED STATES OF AMERICA15B. CONTRACTOR/OFFEROR
(Signature of Contracting Officer)(Signature of person authorized to sign)
16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)
(a) By completing Items 8 and 15, and returning
DCSO-NEW CUMBERLAND
5404 J AVE BLDG 404
NEW CUMBERLAND PA 17070-5059
USA
15C. DATE SIGNED 16C. DATE SIGNED
D. OTHER (Specify type of modification and authority)
3. EFFECTIVE DATE
07/03/2019
See Attached Continuation Sheet(s).
(X)
CHECK ONE
9A. AMENDMENT OF SOLICITATION NO.
9B. DATED (SEE ITEM 11)
13. THIS APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.
IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
CONTINUATION SHEET REFERENCE NO. OF DOCUMENT BEING CONTINUED: PAGE 2 OF 43 PAGES
SP700019Q0024 - 0001
CONTINUED ON NEXT PAGE
The purpose of this amendment is to answer prospective vendors questions.
Question 1.
PWS 3.3
Are the services required on Saturday, Sunday, Federal and Local national holidays?
Answer 1.
No, services would not be required during those days.
Question 2.
PWS 6.4
Please provide the required STIG. The address shown on the solicitation is not found.
Is the MFD STIG applied? If so, please designate the required Version and Release number.
For your reference, I have attached the V2 R11 which was released in 2018.
Answer 2.
Basic STIG configuration is ok. See ATTACHMENT 1 for updated STIG Information.
Question 3.
Page. 5-44 Regarding pricing of currency, Is JPY acceptable for this proposal and bill?
Answer 3.
Please use US dollars as specified in the solicitation.
Question 4.
Attachment1 3.3 Maintenance and repairs Regarding maintenance time, our service is currently 9:00am-5:00pm. But we are able to three hour service response for designated critical machines. Is it acceptable?
Answer 4.
Attachment1 3.3 – Yes, that is fine. As long as they are able to support for a majority of the day.
Question 5.
Attachment1 5.1
NETWORKING FUNCTIONALITY
Regarding test machine, the equipment required full option config? Or is it acceptable the basic configuration?
Answer 5.
Attachment1 5.1 –Basic config is ok.
Question 6.
Attachment 6.2 Our equipment is scanner, controller and printer in one unit. And it does not have operating systems. In other word, our equipment does not have any color controller with operating sytems. Is it acceptable for you?
Answer 6.
We would need a little more info on how their setup is, but based on what we are currently using I do not think this will cause a problem. The equipment must meet or exceed the minimum specifications in order to be technically acceptable.
Question 7.
Attachment1 11.1 Removal and disposal Who is responsible for HDD removal?
Answer 7.
The winning vendor will be in-charge of HDD removal and must be turn in all HDDs to the DLA Data Management Services POC listed on the Award.
Question 8.
Enclosure 1a Minimum Scanner Specification Power requirements 100-240VAC. Do we need to fit all range voltage? Our equipment designed 100VAC for color equipment, and 200VAC for Black and White equipment.
Answer 8.
The voltage is an acceptable range, that would allow the equipment to function on base.
Question 9.
Enclosure 1b.
There are 7configurations on page of configurations options. Could you explain which config match each models. Which configurations need to refer to pricing page?
Answer 9.
Enclosure 1b – Meeting the minimum requirements would be all that is required (Number 1 (basic configuration) See Revised enclosure 1b.).
Configuration Number 1 (Basic Configuration) Engine.
Hard drives for engine and controller.
Original document handler.
Standard Paper feed delivery.
High Capacity Paper feed delivery.
Controller.
Inserter Module.
Standard Finisher.
Operating system.
Postscript handling option.
Oversized High Capacity Paper feed delivery
Fax (Color device only)
Revised 1b.
CONFIGURATION OPTIONS
SP7000-19-Q-0024 0001
UNCLASSIFIED
MULTIFUNCTION DEVICES AND NETWORK
PRINTERS STIG
REVISION HISTORY
Version 2, Release 13
25 January 2019
Developed by DISA for the DoD
ATTACHMENT 1
STIG Information
Multifunction Devices and Network Printers STIG Revision History, V2R13 DISA 25 January 2019 Developed by DISA for the DoD
REVISION HISTORY
Revision Number
Document Revised Description of Change Release Date
V2R13 - MFD and Network Printers
STIG
- V-6777 - Updated MFD01.001 (V-6777) to state "call-home" feature is disallowed.
- V-6779 - Updated MFD01.003 (V-6779) to state "call-home" feature is disallowed.
- V-6780 - Updated MFD02.004 (V-6780) to state "call-home" feature is disallowed.
- V-6782 - Updated MFD02.002 (V-6782) to state "call-home" feature is disallowed.
25 January 2019
V2R12 - MFD and Network Printers
STIG
- Updated section 1.1 to specify that directly connected printing devices, such as USB printers are out of scope.
26 October 2018
V2R11 - MFD and Network Printers
STIG
- MFD04.001 - Added AirPrint and WiFi Direct to the check as not being allowed to send print jobs directly to a printer or MFD. Removed Responsibility.
26 January 2018
V2R10 - MFD and Network Printers
STIG
- MFD01.002 - Removed requirement since it did not address a vulnerablity or provide any security advantage.
28 July 2017
V2R9 - MFD and Network Printers
STIG
- MFD06.002 - Update DoDD C-5200.19 reference to DoDD 8500.01E.
- Removed Information Assurance Officer from Responsibility section.
27 January 2017
V2R8 - MFD and Network Printers
STIG
- MFD and Network Printers Overview
- MFD04.001 - Added AirPrint reference to check.
- Added Section 1.7 Product Approval Disclaimer.
- Added Section 2.6 Wireless Direct Printing.
22 January 2016
V2R7 - MFD and Network Printers
STIG
- MFD02.001 - Update Vulnerability Discussion and Content Check.
23 October 2015
V2R6 - MFD and Network Printers
STIG
- Removed references to SPAN STIG. 24 July 2015
V2R5 - MFD and Network
- MFD06.002 - Update Rule Title, Vulnerability Discussion, Check, and Fix Text.
25 April 2015
ATTACHMENT 1
Multifunction Devices and Network Printers STIG Revision History, V2R13 DISA 25 January 2019 Developed by DISA for the DoD
REVISION HISTORY
Revision Number
Document Revised Description of Change Release Date
Printers
STIG
- MFD06.006 - Update Rule Title, Vulnerability Discussion, Check, and Fix Text.
V2R4 - MFD and Network Printers
STIG
- MFD02.003 - Update Rule Title, Check, and Fix Content.
31 October 2014
V2R3 - MFD and Network Printers
STIG
- Broke out from SPAN STIG package.
- Created independent README and RevHistory.
25 October 2013
ATTACHMENT 1
U_Multifunction_Device_and_Network_Printers_STIG_V2R13_Manual‐xccdf <?xml version="1.0" encoding="utf‐8"?><?xml‐stylesheet type='text/xsl' href='STIG_unclass.xsl'?><Benchmark xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" xmlns:xsi="http://www.w3.org/2001/XMLSchema‐instance" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:dc="http://purl.org/dc/elements/1.1/" id="MULTI‐FUNCTION_DEVICE" xml:lang="en" xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.1 http://nvd.nist.gov/schema/xccdf‐1.1.4.xsd http://cpe.mitre.org/dictionary/2.0 http://cpe.mitre.org/files/cpe‐dictionary_2.1.xsd" xmlns="http://checklists.nist.gov/xccdf/1.1"><status date="2019‐01‐04">accepted</status><title>Multifunction Device and Network Printers STIG</title><description>Multifunction Device and Network Printers (MFD) STIG includes the computing requirements for Multifunction Device and Network Printers operating to support the DoD. The Multifunction Device and Network Printers STIG must also be applied for each site using Multifunction Devices and Network Printers. Comments or proposed revisions to this document should be sent via e‐mail to the following address: disa.stig_spt@mail.mil.</description><notice id="terms‐of‐use" xml:lang="en"></notice><reference href="http://iase.disa.mil"><dc:publisher>DISA</dc:publisher><dc:source>STIG.DOD.MI L</dc:source></reference><plain‐text id="release‐info">Release: 13 Benchmark Date:
25 Jan 2019</plain‐text><version>2</version><Profile id="MAC‐1_Classified"><title>I ‐ Mission Critical Classified</title><description><ProfileDescription></ProfileDescription> ;</description><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6781" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783" selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6796" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6801" selected="true" /><select idref="V‐6802" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /><select idref="V‐6805" selected="true" /><select idref="V‐6806" selected="true" /></Profile><Profile id="MAC‐1_Public"><title>I ‐ Mission Critical Public</title><description><ProfileDescription></ProfileDescription></d escription><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783" selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /></Profile><Profile id="MAC‐1_Sensitive"><title>I ‐ Mission Critical Sensitive</title><description><ProfileDescription></ProfileDescription>
</description><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6781" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783"
ATTACHMENT 1
selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6796" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6801" selected="true" /><select idref="V‐6802" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /><select idref="V‐6805" selected="true" /><select idref="V‐6806" selected="true" /></Profile><Profile id="MAC‐2_Classified"><title>II ‐ Mission Support Classified</title><description><ProfileDescription></ProfileDescription> ;</description><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6781" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783" selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6796" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6801" selected="true" /><select idref="V‐6802" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /><select idref="V‐6805" selected="true" /><select idref="V‐6806" selected="true" /></Profile><Profile id="MAC‐2_Public"><title>II ‐ Mission Support Public</title><description><ProfileDescription></ProfileDescription></d escription><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783" selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /></Profile><Profile id="MAC‐2_Sensitive"><title>II ‐ Mission Support Sensitive</title><description><ProfileDescription></ProfileDescription>
</description><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6781" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783" selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6796" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6801" selected="true" /><select idref="V‐6802" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /><select idref="V‐6805" selected="true" /><select idref="V‐6806" selected="true" /></Profile><Profile id="MAC‐3_Classified"><title>III ‐ Administrative Classified</title><description><ProfileDescription></ProfileDescription> ;</description><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6781" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783"
ATTACHMENT 1
selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6796" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6801" selected="true" /><select idref="V‐6802" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /><select idref="V‐6805" selected="true" /><select idref="V‐6806" selected="true" /></Profile><Profile id="MAC‐3_Public"><title>III ‐ Administrative Public</title><description><ProfileDescription></ProfileDescription></d escription><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783" selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /></Profile><Profile id="MAC‐3_Sensitive"><title>III ‐ Administrative Sensitive</title><description><ProfileDescription></ProfileDescription>
</description><select idref="V‐6777" selected="true" /><select idref="V‐6779" selected="true" /><select idref="V‐6780" selected="true" /><select idref="V‐6781" selected="true" /><select idref="V‐6782" selected="true" /><select idref="V‐6783" selected="true" /><select idref="V‐6784" selected="true" /><select idref="V‐6790" selected="true" /><select idref="V‐6794" selected="true" /><select idref="V‐6796" selected="true" /><select idref="V‐6797" selected="true" /><select idref="V‐6798" selected="true" /><select idref="V‐6799" selected="true" /><select idref="V‐6800" selected="true" /><select idref="V‐6801" selected="true" /><select idref="V‐6802" selected="true" /><select idref="V‐6803" selected="true" /><select idref="V‐6804" selected="true" /><select idref="V‐6805" selected="true" /><select idref="V‐6806" selected="true" /></Profile><Group id="V‐6777"><title>MFD Protocol TCP/IP</title><description><GroupDescription></GroupDescription></descr iption><Rule id="SV‐6999r2_rule" severity="medium" weight="10.0"><version>MFD01.001</version><title>The MFD or Network Printer must not enable network protocols other than TCP/IP.</title><description><VulnDiscussion>The greater the number of protocols allowed active on the network the more vulnerabilities there will be available to be exploited. This also prevents accidental implementation of a “call‐ home” feature that is not allowed.</VulnDiscussion><FalsePositives></FalsePositives><Fal seNegatives></FalseNegatives><Documentable>false</Documentable> ;<Mitigations></Mitigations><SeverityOverrideGuidance></Severi tyOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPar tyTools></ThirdPartyTools><MitigationControl></MitigationControl& gt;<Responsibility></Responsibility><IAControls></IAControls&g t;</description><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext
ATTACHMENT 1
fixref="F‐6430r2_fix">Configure the MFD or Network Printer to disable all protocols except TCP/IP.</fixtext><fix id="F‐6430r2_fix" /><check system="C‐2941r2_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will verify the configuration settings in the MFD or Network Printer to ensure the only protocol enabled is TCP/IP.
If a protocol other than TCP/IP is enabled, this is a finding.</check‐content></check></Rule></Group><Group id="V‐6779"><title>MFD/Printer Firewall/Router Rule Perimeter</title><description><GroupDescription></GroupDescription></de scription><Rule id="SV‐7001r2_rule" severity="medium" weight="10.0"><version>MFD01.003</version><title>A firewall or router rule must block all ingress and egress traffic from the enclave perimeter to the MFD or Network Printer.</title><description><VulnDiscussion>Access to the MFD or printer from outside the enclave network could lead to a denial of service caused by a large number of large print files being sent to the device. Ability for the MFD or printer to access addresses outside the enclave network could lead to a compromise of sensitive data caused by forwarding a print file to a location outside of the enclave network. This also prevents accidental implementation of a “call‐home” feature that is not allowed.</VulnDiscussion><FalsePositives></FalsePositives><Fal seNegatives></FalseNegatives><Documentable>false</Documentable> ;<Mitigations></Mitigations><SeverityOverrideGuidance></Severi tyOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPar tyTools></ThirdPartyTools><MitigationControl></MitigationControl& gt;<Responsibility></Responsibility><IAControls></IAControls&g t;</description><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6432r2_fix">Configure a firewall or router rule to block all ingress and egress traffic from the enclave perimeter to the MFD or Network Printer.</fixtext><fix id="F‐6432r2_fix" /><check system="C‐2954r2_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will verify that a firewall or router rule blocks all ingress and egress traffic from the enclave perimeter to the MFD or Network Printer.
If a firewall or router does not block all ingress and egress traffic from the enclave perimeter to the MFD or Network Printer, this is a finding.</check‐content></check></Rule></Group><Group id="V‐6780"><title>MFD Firmware</title><description><GroupDescription></GroupDescription></des cription><Rule id="SV‐7002r2_rule" severity="medium" weight="10.0"><version>MFD02.004</version><title>The MFD or Network Printer must employ the most current firmware available.</title><description><VulnDiscussion>MFD devices or printers utilizing old firmware can expose the network to known vulnerabilities leading to a
ATTACHMENT 1
denial of service or a compromise of sensitive data. While the MFD must use the most current firmware available, it must not use a “call‐home” feature that is not allowed.</VulnDiscussion><FalsePositives></FalsePositives><Fal seNegatives></FalseNegatives><Documentable>false</Documentable> ;<Mitigations></Mitigations><SeverityOverrideGuidance></Severi tyOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPar tyTools></ThirdPartyTools><MitigationControl></MitigationControl& gt;<Responsibility></Responsibility><IAControls></IAControls&g t;</description><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6433r2_fix">If the MFD or printer cannot be upgraded replace it.
If the MFD or printer can be upgraded but is not using the latest release of the firmware, upgrade the firmware.</fixtext><fix id="F‐6433r2_fix" /><check system="C‐2965r2_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will verify that the MFD or Network Printer are flash upgradeable and are configured to use the most current firmware available.
Ensure any “call‐home” feature is disabled.
If the MFD or Network Printer is not flash upgradeable, this is a finding.
If the MFD or Network Printer is not configured with the most current firmware, this is a finding.
If the MFD or Network Printer has the “call‐home” feature enabled, this is a finding.</check‐content></check></Rule></Group><Group id="V‐6781"><title>MFD SNMP Community Strings </title><description><GroupDescription></GroupDescription></description ><Rule id="SV‐7003r2_rule" severity="high" weight="10.0"><version>MFD02.001</version><title>The default passwords and SNMP community strings of all management services have not been replaced with complex passwords.</title><description><VulnDiscussion>There are many known vulnerabilities in the SNMP protocol and if the default community strings and passwords are not modified an unauthorized individual could gain control of the MFD or printer. This could lead to a denial of service or the compromise of sensitive data.
The SA will ensure the default passwords and SNMP community strings of all management services are replaced with complex passwords.
</VulnDiscussion><FalsePositives></FalsePositives><FalseNegati ves></FalseNegatives><Documentable>false</Documentable><Mit igations></Mitigations><SeverityOverrideGuidance></SeverityOverri deGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools& gt;</ThirdPartyTools><MitigationControl></MitigationControl><R esponsibility></Responsibility><IAControls></IAControls></desc
ATTACHMENT 1
ription><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6434r1_fix">Develop a plan to coordinate the modification of the default passwords and SNMP community strings of all management services replacing them with complex passwords. Obtain CM approval of the plan and execute the plan.</fixtext><fix id="F‐6434r1_fix" /><check system="C‐2966r2_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will, with assistance from the SA, verify the default passwords and SNMP community strings of all management services have been replaced with complex passwords.</check‐content></check></Rule></Group><Group id="V‐6782"><title>MFD Configuration State After Power Down or Reboot</title><description><GroupDescription></GroupDescription></descr iption><Rule id="SV‐7004r2_rule" severity="high" weight="10.0"><version>MFD02.002</version><title>The MFD or Network Printer must maintain configuration state (e.g., passwords, service settings) after a power down or restart.</title><description><VulnDiscussion>If the MFD does not maintain it state over a power down or restart, it will expose the network to all of the vulnerabilities that where mitigated by the modifications made to its configuration state. This also prevents accidental implementation of a “call‐home” feature that is not allowed.</VulnDiscussion><FalsePositives></FalsePositives><Fal seNegatives></FalseNegatives><Documentable>false</Documentable> ;<Mitigations></Mitigations><SeverityOverrideGuidance></Severi tyOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPar tyTools></ThirdPartyTools><MitigationControl></MitigationControl& gt;<Responsibility></Responsibility><IAControls></IAControls&g t;</description><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6435r2_fix">If the MFD or Network Printer cannot be configured to maintain state, then replace the MFD with a MFD that will maintain its configuration state (passwords, service settings, etc) after a power down or restart.</fixtext><fix id="F‐6435r2_fix" /><check system="C‐2968r2_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will verify the MFD or Network Printer maintains its configuration state after a power down or restart. Review the device documentation and/or confirm through demonstration to verify the MFD maintains configuration settings.
If the MFD or Network Printer does not maintain its configuration state, this is a finding.</check‐content></check></Rule></Group><Group id="V‐6783"><title>MFD Management Protocols</title><description><GroupDescription></GroupDescription></de scription><Rule id="SV‐7005r2_rule" severity="medium"
ATTACHMENT 1
weight="10.0"><version>MFD02.003</version><title>Management protocols, with the exception of HTTPS and SNMPv3, must be disabled at all times except when necessary.</title><description><VulnDiscussion>Unneeded protocols expose the device and the network to unnecessary vulnerabilities.</VulnDiscussion><FalsePositives></FalsePositives> ;<FalseNegatives></FalseNegatives><Documentable>false</Documen table><Mitigations></Mitigations><SeverityOverrideGuidance>< ;/SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><
ThirdPartyTools></ThirdPartyTools><MitigationControl></Mitigation Control><Responsibility>System Administrator</Responsibility><IAControls>DCPP‐1</IAControls></de scription><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6436r2_fix">Disable all management protocols except HTTPS and SNMPv3 unless approval has been granted by the organization's AO/ISSM.</fixtext><fix id="F‐6436r2_fix" /><check system="C‐2969r2_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>Verify that all management protocols are disabled unless approved by the organization's
AO/ISSM.
Protocols may be enabled temporarily if needed to upgrade firmware or configure the device, but must be disabled immediately when this activity is completed. HTTPS and SNMPv3 may be used but must be configured in accordance with the requirements of the Network Infrastructure STIG.
If management protocols other than HTTPS and SNMPv3 are enabled unnecessarily or without AO/ISSM approval, this is a finding.</check‐content></check></Rule></Group><Group id="V‐6784"><title> MFD or a printer can be managed from any IP</title><description><GroupDescription></GroupDescription></descripti on><Rule id="SV‐7009r1_rule" severity="high" weight="10.0"><version>MFD02.005</version><title>There is no restriction on where a MFD or a printer can be remotely managed.</title><description><VulnDiscussion>Since unrestricted access to the MFD or printer for management is not required the restricting the management interface to specific IP addresses decreases the exposure of the system to malicious actions. If the MFD or printer is compromised it could lead to a denial of service or a compromise of sensitive data.
The SA will ensure devices can only be remotely managed by SA’s or printer administrators from specific IPs (SA workstations and print spooler).</VulnDiscussion><FalsePositives></FalsePositives><Fa lseNegatives></FalseNegatives><Documentable>false</Documentable&g t;<Mitigations></Mitigations><SeverityOverrideGuidance></Sever ityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPa rtyTools></ThirdPartyTools><MitigationControl></MitigationControl ><Responsibility>System
ATTACHMENT 1
Administrator</Responsibility><IAControls>DCBP‐1</IAControls></de scription><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6447r1_fix">Restrict access to the MFD's or printer's management function to a specific set of IP addresses. If the device lacks this functionality use an ACL in a router, firewall or switch to restrict the access.</fixtext><fix id="F‐6447r1_fix" /><check system="C‐2984r1_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will, with the assistance of the SA, verify that the MFD or printer can only be remotely managed by SA or printer administrator from specific IPs (SA workstations and print spooler). Look for list that restricts the protocol used for administrative access to specific IP addresses.</check‐content></check></Rule></Group><Group id="V‐6790"><title>Print Services Restricted to Port 9100 and/or LPD</title><description><GroupDescription></GroupDescription></descript ion><Rule id="SV‐7015r1_rule" severity="low" weight="10.0"><version>MFD03.001</version><title>Print services for a MFD or printer are not restricted to Port 9100 and/or LPD (Port 515).
Where both Windows and non‐Windows clients need services from the same device, both Port 9100 and LPD can be enabled simultaneously.
</title><description><VulnDiscussion>Printer services running on ports other than the known ports for printing cannot be monitored on the network and could lead to a denial of service it the invalid port is blocked by a network administrator responding to an alert from the IDS for traffic on an unauthorized port.</VulnDiscussion><FalsePositives></FalsePositives><FalseN egatives></FalseNegatives><Documentable>false</Documentable>&l t;Mitigations></Mitigations><SeverityOverrideGuidance></SeverityO verrideGuidance><PotentialImpacts>Print clients configured to use the unauthorized port(s) will not be able to print until they are reconfigured to use the correct port.</PotentialImpacts><ThirdPartyTools></ThirdPartyTools><Mi tigationControl></MitigationControl><Responsibility>System Administrator</Responsibility><IAControls>DCBP‐1</IAControls></de scription><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6456r1_fix">Develop a plan to coordinate the reconfiguration of the printer servers and clients so that print services runs only on authorized ports.
Obtain CM approval of the plan and implement the plan.</fixtext><fix id="F‐6456r1_fix" /><check system="C‐2994r1_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will, with the assistance of the SA, verify that the MFD or printer print services are restricted to LPD or port 9100.
ATTACHMENT 1
Where both Windows and non‐Windows clients need services from the same device, both Port 9100 and LPD can be enabled simultaneously.
</check‐content></check></Rule></Group><Group id="V‐6794"><title>MFD/Printer Restrict Jobs Only From Print Spooler</title><description><GroupDescription></GroupDescription></desc ription><Rule id="SV‐7019r3_rule" severity="medium" weight="10.0"><version>MFD04.001</version><title>A MFD or printer is not configured to restrict jobs to those from print spoolers.
</title><description><VulnDiscussion>If MFDs or printers are not restricted to accept print jobs only from print spoolers that authenticate the user and log the job, a denial of service can be created by the MFD or printer accepting one or more large print jobs from an unauthorized user.
The SA will ensure MFDs and printers are configured to restrict jobs only to print spoolers, not directly from users.
Mobile device print jobs must be sent to a print spooler, they must not be sent directly from a mobile device to a MFD or printer that supports direct wireless printing (e.g., AirPrint, Wi‐Fi Direct, etc.).
The configuration is accomplished by restricting access, by IP, to those of the print spooler and SAs. If supported, IP restriction is accomplished on the device, or if not supported, by placing the device behind a firewall, switch or router with an appropriate discretionary access control list.
</VulnDiscussion><FalsePositives></FalsePositives><FalseNegati ves></FalseNegatives><Documentable>false</Documentable><Mit igations></Mitigations><SeverityOverrideGuidance></SeverityOverri deGuidance><PotentialImpacts>Client systems that are configured to bypass the print server that spools print jobs will lose access to the printer until reconfigured.</PotentialImpacts><ThirdPartyTools></ThirdPartyTools&g t;<MitigationControl></MitigationControl><Responsibility></Res ponsibility><IAControls></IAControls></description><reference><dc:ti tle>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6461r2_fix">Reconfigure the device to restrict access, by IP, to those of the print spoolers and SAs. If the device does not support this functionality, place the device behind a firewall, switch or router with an appropriate discretionary access control list. Disable direct wireless printing on the MFD or printer.</fixtext><fix id="F‐6461r2_fix" /><check system="C‐2998r4_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will, with the assistance of the SA, verify that MFDs and printers are configured to restrict jobs only to print spoolers, not directly from users.
If print jobs are sent directly to the MFD or printer, this is a finding.
ATTACHMENT 1
If direct wireless printing (e.g., AirPrint, Wi‐Fi Direct, etc.), is enabled on the MFD or printer, this is a finding.</check‐content></check></Rule></Group><Group id="V‐6796"><title>MFD Authorized Users Restrictions</title><description><GroupDescription></GroupDescription>< /description><Rule id="SV‐7021r1_rule" severity="medium" weight="10.0"><version>MFD05.001</version><title>Print spoolers are not configured to restrict access to authorized users and restrict users to managing their own individual jobs. </title><description><VulnDiscussion>If unauthorized users are allowed access to the print spooler they can queue large print file creating a denial of service for other users. If users are not restricted to manipulating only files they created, they could create ad denial of service by changing the print order of existing files or deleting other users files.
The SA will ensure print spoolers are configured to restrict access to authorized user and restrict users to managing their own individual jobs.</VulnDiscussion><FalsePositives></FalsePositives><FalseN egatives></FalseNegatives><Documentable>false</Documentable>&l t;Mitigations></Mitigations><SeverityOverrideGuidance></SeverityO verrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyT ools></ThirdPartyTools><MitigationControl></MitigationControl>
<Responsibility>System Administrator</Responsibility><IAControls>ECAN‐1, IAIA‐1, IAIA‐2</IAControls></description><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6463r1_fix">Configure the print spoolers to restrict access to authorized users and restrict users to managing their own individual jobs.</fixtext><fix id="F‐6463r1_fix" /><check system="C‐3002r1_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will, with the assistance of the SA, verify that the print spoolers are configured to restrict access to authorized users and restrict users to managing their own individual jobs.</check‐content></check></Rule></Group><Group id="V‐6797"><title>MFD and Spooler Auditing</title><description><GroupDescription></GroupDescription></des cription><Rule id="SV‐7022r1_rule" severity="medium" weight="10.0"><version>MFD06.001</version><title>The devices and their spoolers do not have auditing enabled. </title><description><VulnDiscussion>Without auditing the identification and prosecution of an individual that performs malicious actions is difficult if not impossible.</VulnDiscussion><FalsePositives></FalsePositives><
FalseNegatives></FalseNegatives><Documentable>false</Documentable ><Mitigations></Mitigations><SeverityOverrideGuidance></Sev erityOverrideGuidance><PotentialImpacts></PotentialImpacts><Third PartyTools></ThirdPartyTools><MitigationControl></MitigationContr ol><Responsibility>System Administrator</Responsibility><IAControls>ECAR‐1, ECAR‐2, ECAR‐3</IAControls></description><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS
ATTACHMENT 1
Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6465r1_fix">Configure the devices and their spoolers have auditing fully enabled.</fixtext><fix id="F‐6465r1_fix" /><check system="C‐3005r1_chk"><check‐content‐ref name="M" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>The reviewer will, with the assistance of the SA, verify that devices and their spoolers have auditing fully enabled.</check‐content></check></Rule></Group><Group id="V‐6798"><title>MFD/Printer Security Policy </title><description><GroupDescription></GroupDescription></description ><Rule id="SV‐7023r3_rule" severity="low" weight="10.0"><version>MFD06.002</version><title>Implementation of an MFD and printer security policy for the protection of classified information.
</title><description><VulnDiscussion>Department of Defense Manual 5200.01, "Protection of Classified Information" provides policy, assigns responsibilities, and provides procedures for the designation, marking, protection, and dissemination of controlled unclassified information (CUI) and classified information. DoDM 5200.01, Volume 3, Section 14 mandates that organizations identify equipment used for classified processing and develop security procedures to safeguard these devices.
This requires that each organization have an MFD and printer security policy that lists the following safeguards:
a. Prevent unauthorized access to that information, including by repair or maintenance personnel.
b. Ensure that repair procedures do not result in unauthorized dissemination of or access to classified information.
c. Replace and destroy equipment parts in the appropriate manner when classified information cannot be removed.
d. Ensure that appropriately knowledgeable, cleared personnel inspect equipment and associated media used to process classified information before the equipment is removed from protected areas to ensure there is no retained classified information.
e. Ensure MFD and printers used to process classified information are certified and accredited in accordance with DoDD 8500.01E.
f. Ensure that MFD and printers address issues concerning compromising emanations in accordance with DoDD 8500.01E.</VulnDiscussion><FalsePositives></FalsePositives><Fa lseNegatives></FalseNegatives><Documentable>false</Documentable&g t;<Mitigations></Mitigations><SeverityOverrideGuidance></Sever ityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPa rtyTools></ThirdPartyTools><MitigationControl></MitigationControl ><Responsibility></Responsibility><IAControls>DCBP‐1, ECAN‐1, ECIC‐1, IAIA‐1, PECS‐1, PECS‐2, PEDD‐1</IAControls></description><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6467r2_fix">Develop and implement an MFD and printer security policy
ATTACHMENT 1
consistent with DoDM 5200.01, Volume 3, Section 14.</fixtext><fix id="F‐6467r2_fix" /><check system="C‐3006r3_chk"><check‐content‐ref name="I" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>Obtain and review the organization's MFD and printer security policy. If none is provided, this is a finding. If it does not prescribe the appropriate safeguards listed below, this is a finding.
Safeguards to be listed in the organization's MFD and printer security policy;
a. Prevent unauthorized access to that information, including by repair or maintenance personnel.
b. Ensure that repair procedures do not result in unauthorized dissemination of or access to classified information.
c. Replace and destroy equipment parts in the appropriate manner when classified information cannot be removed.
d. Ensure that appropriately knowledgeable, cleared personnel inspect equipment and associated media used to process classified information before the equipment is removed from protected areas to ensure there is no retained classified information.
e. Ensure MFD and printers used to process classified information are certified and accredited in accordance with DoDD 8500.01E.
f. Ensure that MFD and printers address issues concerning compromising emanations in accordance with DoDD 8500.01E.</check‐content></check></Rule></Group><Group id="V‐6799"><title>MFD Level of Audit and Reviewing</title><description><GroupDescription></GroupDescription></de scription><Rule id="SV‐7024r2_rule" severity="low" weight="10.0"><version>MFD06.006</version><title>The level of audit has not been established or the audit logs being collected for the devices and print spoolers are not being reviewed.</title><description><VulnDiscussion>If inadequate information is captured in the audit, the identification and prosecution of malicious user will be very difficult. If the audits are not regularly reviewed suspicious activity may go undetected for a long time. Therefore, the level of auditing for MFDs, printers, and print spoolers must be defined and personnel identified to review the audit logs.
</VulnDiscussion><FalsePositives></FalsePositives><FalseNegati ves></FalseNegatives><Documentable>false</Documentable><Mit igations></Mitigations><SeverityOverrideGuidance></SeverityOverri deGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools& gt;</ThirdPartyTools><MitigationControl></MitigationControl><R esponsibility>Information Assurance Officer</Responsibility><IAControls>ECAR‐1, ECAR‐2, ECAR‐3, ECAT‐1, ECAT‐2</IAControls></description><reference><dc:title>DPMS Target Multifunction Device ‐ MFD</dc:title><dc:publisher>DISA</dc:publisher><dc:type>DPMS Target</dc:type><dc:subject>Multifunction Device ‐ MFD</dc:subject><dc:identifier>551</dc:identifier></reference><fixtext fixref="F‐6470r2_fix">Define the level of auditing and identify personnel responsible for reviewing audit logs of MFDs, printers, and print spoolers.</fixtext><fix id="F‐6470r2_fix" /><check system="C‐3009r2_chk"><check‐content‐ref name="I" href="DPMS_XCCDF_Benchmark_MULTI‐FUNCTION DEVICE.xml" /><check‐content>Obtain and review the organization's MFD and printer security policy. If the level of
ATTACHMENT 1
auditing has not been established, this is a finding. If personnel have not been identified to regularly review MFD, printer, and print spooler logs, this is a finding.</check‐content></check></Rule></Group><Group id="V‐6800"><title>MFD Classified Network</title><description><GroupDescription></GroupDescription></desc ription><Rule id="SV‐7025r2_rule" severity="high" weight="10.0"><version>MFD07.001</version><title>MFDs with print, copy, scan, or fax capabilities must be prohibited on classified networks without the approval of the DAA.</title><description><VulnDiscussion>MFDs with print, copy, scan, or fax capabilities, if compromised, could lead to the compromise of classified data or the compromise of the network.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.