Check: MFD07.001
Multifunction Device and Network Printers STIG:
MFD07.001
(in versions v2 r14 through v2 r9)
Title
MFDs with print, copy, scan, or fax capabilities must be prohibited on classified networks without the approval of the DAA. (Cat I impact)
Discussion
MFDs with print, copy, scan, or fax capabilities, if compromised, could lead to the compromise of classified data or the compromise of the network. The IAO will ensure MFDs with copy, scan, or fax capabilities are not allowed on classified networks unless approved by the DAA.
Check Content
The reviewer will interview the IAO to verify that MFDs with print, copy, scan, or fax capabilities are prohibited on classified networks unless approved by the DAA.
Fix Text
Remove the MFD from the classified network until DAA approval is obtained.
Additional Identifiers
Rule ID: SV-7025r2_rule
Vulnerability ID: V-6800
Group Title: MFD Classified Network
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
The organization configures the information system to provide only essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |