SECURITY. Konica Minolta s industry-leading security standards SECURITY



Similar documents
SECURITY WITHOUT SACRIFICE

fundamentals of security Whitepaper whitepaper

User Authentication Job Tracking Fax Transmission via RightFax Server Secure Printing Functions HDD/Memory Security Fax to Ethernet Connection Data

User s Guide [Security Operations]

User s Guide. Security Operations Ver. 1.02

User Authentication Job Tracking Fax Transmission via RightFax Server Secure Printing Functions HDD/Memory Security Fax to Ethernet Connection

SeCUritY. Safeguarding information Within Documents and Devices. imagerunner ADVANCE Solutions. ADVANCE to Canon MFP security solutions.

Samsung Security Solutions

Fundamentals of security. Information Security White Paper

I WANT EFFICIENT WORKFLOWS, HIGHER PRODUCTIVITY AND LOWER COSTS

bizhub C3850/C3350 USER S GUIDE Applied Functions

Are your multi-function printers a security risk? Here are five key strategies for safeguarding your data

Security White Paper. for KYOCERA MFPs and Printers

Security Solutions. Concerned about information security? You should be!

Security White Paper for KYOCERA MFPs and Printers

Standard Information Communications Technology. Multifunction Device. January 2013 Version 2.2. Department of Corporate and Information Services

PageScope Enterprise Suite: interlocking solutions to manage your printer and MFP fleet more productively.

I-Fax (Internet Fax) 1: Basic Overview. 2: Benefits to the customer. Machines included:

Office system bizhub 250 bizhub 250 Compact creativity

Created by Hotline Support Konica Minolta Hotline Support (UK) V1.2

Operating Instructions (For User Authentication)

Setting Up Scan to SMB on TaskALFA series MFP s.

Xerox WorkCentre 5325/5330/5335 Security Function Supplementary Guide

WorkCentre 7425/7428/7435 Security Function Supplementary Guide

Administrator's Guide

Enabling bizhub HDD Security Features

PageScope Enterprise Suite 3.0

Scanning Guide for Current Colour Machines

Ricoh Security Solutions Comprehensive protection for your documents and information. ecure. proven. trusted

SSL Guide. (Secure Socket Layer)

ES3452 MFP, ES5462 MFP,

Codici errore Universal Send Kit

7 Network Security. 7.1 Introduction 7.2 Improving the Security 7.3 Internet Security Framework. 7.5 Absolute Security?

Architecture. The DMZ is a portion of a network that separates a purely internal network from an external network.

I WANT OFFICE SOLUTIONS THAT HELP ME ON MY WAY

INFORMATION GOVERNANCE POLICY: NETWORK SECURITY

bizhub C360 / bizhub C552 / bizhub C220 PKI Card System Control Software Security Target

Addressing document imaging security issues

Hard Drive Data Security. Chris Bilello Director, Business Development Konica Minolta Business Solutions U.S.A., Inc.

LDAP Operation Guide

Control scanning, printing and copying effectively with uniflow Version 5. you can

March

Certification Report

This is an example of MFP password entry in the administration mode for hard-disk protection:

Sharp s MFP Security Suite The best of the best in the Market

Information Security Basic Concepts

Issue 2EN. Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation

Xerox D95/D110/D125 Copier/Printer

Newcastle University Information Security Procedures Version 3

Configuring Security for SMTP Traffic

Office system bizhub 600 bizhub 600 Brilliance in black-and-white

Secure Installation and Operation of Your Xerox Multi-Function Device. Version 1.0 August 6, 2012

Information Security Policy September 2009 Newman University IT Services. Information Security Policy

Achieving PCI-Compliance through Cyberoam

KM Embedded. Configuration Guide. AIT Ltd 2 Hawthorn Park Coal Road Leeds LS14 1PQ UK

74% 96 Action Items. Compliance

How To Configure A Rihoh Multi Function Device (Mfd) On A Macbook Or Ipad Or Ipa (Aero) With A Powerpoint 2.5 (A.I.A.A2) With An Ipa

Sharpen your document and data security HP Security solutions for imaging and printing

Quick Scan Features Setup Guide. Scan to Setup. See also: System Administration Guide: Contains details about setup.

Print Security and Identity Authorization

NETASQ SSO Agent Installation and deployment

Xerox WorkCentre 4260 vs. Samsung SCX-6555N. Competitive Assessment. WorkCentre 4260 Multifunction Printer. Competitive Assessment

IEEE 2600-series Standards for Hardcopy Device Security

Web Security School Final Exam

LIVE CHAT CLOUD SECURITY Everything you need to know about live chat and communicating with your customers securely

CONTENTS. Contents > 3

KM-1820 FS-1118MFP. Network Scanner Setup Guide

NERC CIP Requirements and Lexmark Device Security

FileCloud Security FAQ

File Management Utility User Guide

IBX Business Network Platform Information Security Controls Document Classification [Public]

I want EDUCATION with personal services to keep

Legal Notes. Regarding Trademarks KYOCERA MITA Corporation

PageScope Enterprise Suite 3.2

Hosted Testing and Grading

MAXIMUM DATA SECURITY with ideals TM Virtual Data Room

HIPAA Security Compliance for Konica Minolta bizhub MFPs

Interwoven WorkSite Framework* User s Guide

CAC/PIV PKI Solution Installation Survey & Checklist

7.1. Remote Access Connection

Smart Card Installation and Configuration Guide

INDIVIDUAL bizhub ENHANCEMENT

Scan to FTP Guide. Version 0 ENG

Black & White Scanning Guide

A Decision Maker s Guide to Securing an IT Infrastructure

CTS2134 Introduction to Networking. Module Network Security

Using a Firewall General Configuration Guide

TONAQUINT DATA CENTER, INC. CLOUD SECURITY POLICY & PROCEDURES. Tonaquint Data Center, Inc Cloud Security Policy & Procedures 1

Protecting the Palace: Cardholder Data Environments, PCI Standards and Wireless Security for Ecommerce Ecosystems

KM-1820 FS-1118MFP. Network Scanner Setup Guide

NSi Mobile Administrator Guide. Version 6.2

Transcription:

Konica Minolta s industry-leading security standards In the digital age, we have seen global communications undergo unprecedented growth and the potential for security breaches has grown in parallel. In any business environment, the day-to-day use of copy, print, scan and fax systems as the elementary components of work processes and workflows, makes MFDs (multifunctional devices) indispensable at many levels. As a consequence, it is paramount that these devices are given the protection needed to withstand on-going threats to security. SECURITY

KONICA MINOLTA S SECURITY STANDARDS Konica Minolta s comprehensive range of standard security features and options form a powerful device on which professional solutions can be based: solutions to both detect and prevent security violations and avoid knock-on financial and/or reputational damage at corporate as well as private individual level. Konica Minolta has pioneered this field and remains the industry s leader. Generally MFDs offer a huge range of combined and single functions and choices. Therefore they represent a similarly wide range of potential security loopholes. The scope of MFD security can be grouped into three main sections: Access control/access security Data security/document security Network security Konica Minolta security functions at a glance Access control Copy/print accounting Function restriction Secure printing (lock job) User box password protection User authentication (ID + password) Finger vein scanner IC card reader Event log Data security Data encryption (hard disc) Hard disc data overwrite Hard disc password protection Data auto deletion Network security IP filtering Port and protocol access control SSL/TLS encryption (HTTPS) IP sec support S/MIME 802.1x support Scanning security User authentication POP before SMTP SMTP authentication (SASL) Manual destination blocking Others Service mode protection Admin mode protection Data capturing Unauthorised access lock Copy protection via watermark Encrypted PDF PDF signature PDF encryption via digital ID Copy guard/password copy

COMMON CRITERIA AND ISO 15408 EAL3 Konica Minolta devices are certified (almost without exception) in accordance with the Common Criteria/ISO 15408 EAL3 standard. These are the only internationally recognised standards for IT security testing for digital office products. Printers, copiers and software compliant with ISO 15408 EAL3 certification have all passed a strict security evaluation and are able to satisfy and deliver the kind of security levels that a prudent business operation should seek and rightfully expect. Konica Minolta is the industry leader, setting the benchmark for standard security features! Security is the key element of Konica Minolta s overall strategy... Konica Minolta has a comprehensive range of print and document security features, many of which are standard features for their bizhub range of devices. Rather than certifying optional security kits, Konica Minolta claims to have the widest range of ISO 15408 fully certified MFDs in the market. Source: Quocirca (2011), Market study Closing the print security gap. The market landscape for print security, p. 11. This independent report was written by Quocirca Ltd., a primary research and analysis company specialising in the business impact of information technology and communications (ITC).

ACCESS CONTROL/ ACCESS SECURITY Despite security being high on the agenda in both public and corporate domains, the security risk posed by MFDs is often ignored entirely. While some risks are perhaps identified, they are often simply neglected, especially where sensitive documents and information are concerned. This is especially risky for those MFDs and printers located in public areas, where they can be accessed by staff, contractors and even visitors. Because of the advanced features available on today s MFDs it is easy for information to be copied and distributed within and beyond actual and virtual corporate boundaries. The first logical step is to prevent unauthorised persons being able to operate an MFD. Preventive measures are needed to firstly control access to MFDs, and secondly to establish some kind of security policy reflecting how the devices are used in real life Konica Minolta achieves this while ensuring that none of these measures restrict or limit the user-friendliness of the systems. User authentication The authentication path starts by setting down a policy defining and configuring users and groups of users allowed to work with a device. This can include limitations to access rights; some users are authorised, while others are not, to use various functions such as colour printing. Konica provides three basic technologies for user authentication: 1. Personal password: The password, an alphanumeric code with up to 8 characters, is entered at the MFD panel. These codes can be created for administrators and users. An important aspect is that they can be centrally managed. 2. IC card authentication Most Konica Minolta devices can be fitted with an IC card reader. These are designed for convenience and speed; it is simply a matter of placing the IC card on or near the reader interface. User Password User No/Wrong Password User authentication

3. Biometric finger vein scanner This state-of-the-art design is an advance on more common fingerprint scanners. This system works by comparing the image of the scanned-in finger vein patterns with those in the memory. The finger vein is a biometric which is almost impossible to falsify, and is therefore a means of identifying a person based on an individual physical feature. Unlike fingerprint systems, the finger vein cannot be scanned without the person actually being present and alive. The biometric finger vein scanner means there is no need for people to remember passwords or carry cards. The authentication information can be stored either on the MFD (encrypted) or draw on existing data from the Windows Active Directory. Ongoing information logging of access and usage for each individual device means that any security breaches are detected immediately and flagged. Account tracking Since user control/security requires every user to log in to the output device, the data generated represents an efficient means of monitoring at a number of levels such as user, group and/or department. Whichever of the device functions is used, monochrome or colour copy, printing, scan or fax, they can all be tracked individually, either at the machine or remotely. Analysis and trending of this data provides robust information about MFD usage from a number of different viewpoints: the data can be applied to ensure compliance and to trace unauthorised access; Above all it allows usage to be monitored across the whole fleet of printers and MFDs in a corporate/business/office landscape. Source of the near-infrared rays Camera Vein in the finger Function control/function restriction It is possible for various MFD functions to be limited on an individual user basis. All of the Konica Minolta access control and security functions not only offer greater security against threats which can result in damage in financial and reputational terms, they can also be used as the basis for better governance and enhanced accountability.

DOCUMENT/DATA SECURITY Reflecting the fact that MFDs and printers are often located in public areas, where they can be easily accessed by staff, contractors and visitors, it is necessary to implement appropriate data security policies. The situation is that confidential data, for example stored on the MFD hard disc over a period of time or simply confidential documents lying in the MFD output tray, are initially unprotected and could fall into the wrong hands. Konica Minolta offers a range of tailored security measures to ensure document and data security. HDD security Most printers and MFDs are equipped with hard discs and memory which can retain many gigabytes of possibly confidential data, collected over long periods. Dependable safeguards must therefore be in place to ensure the safekeeping of sensitive corporate information. With Konica Minolta a number of overlapping and intermeshing features provide this assurance: Auto delete function: The auto delete function erases data stored on the hard disc after a set period. Password protection of internal HDD: The read-out of data, obviously including confidential data, on the hard disc requires password entry after HDD removal. The password is linked to the device. The data is therefore not accessible after the HDD is removed from the device. Secure print Output devices are considered a security risk, a risk which should not be underestimated: at the simplest level, documents lying in the output tray can after all be seen and read even by passers-by. There is no simpler way for unauthorised persons to gain access to confidential information. Secure print functionality is a way of ensuring document confidentiality as it specifies that the author of any print job must set a password as a security lock prior to the printing process itself. The secure print function requires the password to be entered directly at the output device, otherwise printing will not start. This is a simple and effective way of preventing confidential documents from falling into the wrong hands. HDD overwriting: The most secure method of formatting a hard disc is that of HDD data overwriting. This is performed in accordance with a number of standards. HDD encryption: On HDDs fitted to Konica Minolta devices the data can be stored in encrypted form based on a 128-bit algorithm encryption system. This feature satisfies corporate data security policies. Once an HDD is encrypted, the data cannot be read/retrieved, even if the HDD is physically removed from the MFD.

Touch & Print/ID & Print Touch & Print is based on authentication via finger vein scanner or IC card reader while ID & Print requires user authentication via ID and password. The printing of the job at hand is immediate at the device, but only after the user at the MFD has been authenticated via an IC card being placed on the unit card reader or by ID confirmation using the finger vein scanner. The advantage of this particular feature is that the user doesn t have to remember a password. Copy protection The copy protection feature adds a watermark to printouts and copies during the printing process. The watermark is barely visible on the original print, but if the document is copied, it moves from the background into the foreground to indicate that it is a copy. Copy guard/password copy This feature adds a concealed security watermark to the original during printing to prevent copies of the document from being made. While barely visible on the protected original document, it is not possible to copy this document again, because the device is blocked for this operation. The password copy feature can override the copy guard and allows copies to be made when the correct password is entered at the MFD panel. PDF digital signature This feature allows a digital signature to be added to the PDF during scanning. After a PDF is written, this allows any changes to be monitored. Fax reception When activated, any faxes received can be kept confidential in a protected user box. User box security User boxes are available for single persons and for groups and allows for any documents to be securely stored on the MFD hard disc before output of the print or copy job. User boxes can be protected using an eight-digit alphanumeric password. When the right password is entered, it is possible to access or view documents in the box. This system effectively ensures that confidential documents and data can only be viewed by authorised persons. PDF encryption Encrypted PDFs are protected by a user password: permission to print or copy the PDF and permission to add PDF contents can be configured during the scanning phase at the MFD. Decryption with Password PDF User PDF Encrypted PDF

NETWORK SECURITY In today s corporate environment, communications and connectivity are indispensable. Konica Minolta office devices have evolved to the point that they act as sophisticated document-processing hubs integral within the network, with the ability to print, copy and scan documents and data to network destinations, as well as send e-mails. This scenario also means that this office technology must cope with and comply with the same security risks and policies as any other network device, and represents a risk if unprotected. In order to avoid any vulnerability from both internal and external network attacks, Konica Minolta ensures that all equipment complies with the strictest security standards. This is achieved by a number of measures including: IP address blocking A basic internal firewall provides an IP address filtering capability and appropriate control of protocol and port access. Port disabling IEEE 802.1x support The standards described in the IEEE802.1x family are the recognised port-based authentication standard for network access control to WANs and LANs. These standards ensure a secure network by shutting down any network communications (e.g. DHCP or HTTP) to unauthorised devices with the exception of authentication requests. The administration mode allows for ports and protocols to be opened, closed, enabled and disabled either directly at the machine or from a remote location. S/MIME Most Konica Minolta MFDs support S/MIME (secure/ multipurpose internet mail extensions) in order to secure e-mail communications from the MFD to specified recipients. S/MIME is used to ensure secure e-mail traffic by en - crypting the e-mail message and its content using a security certificate. SSL/TLS communication This is a protocol which provides protection to communications to and from the device, covering online administration tools and Windows Active Directory transmissions, for example. IPsec support 157921 PC and IP address 162922 PC and IP address 432983 PC and IP address IP address filtering Most bizhub devices also support IPsec to ensure complete encryption of any network data transmitted to and from an MFD. The IP security protocol encrypts all network communications between the local intranet (server, client PC) and the device itself. Konica Minolta Business Solutions Miles Gray Road Basildon Essex SS14 3AR 0800 833864 info@konicaminolta.co.uk www.konicaminolta.co.uk 05/2012