<section title="11.8. Multifunction Devices, Network Printers and Fax Machines"><subsection title="Objective"><paragraph
    title="11.8.1."


><![CDATA[<p>Multifunction devices (MFD’s), network printers and fax machines are used in a secure manner.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="11.8.2."


><![CDATA[<p>This section covers information relating to MFDs, network printers and fax machines connected to either the ISDN, PSTN, HACE or other networks. Further information on MFDs communicating via network gateways can be found in&nbsp;<a title="Data import and export" href="http://nzism.gcsb.govt.nz/ism-document#Section-16876">Section 20.2 - Data Import and Export</a>.</p>]]></paragraph>
</block>
</subsection>
<subsection title="Rationale &amp; Controls"> <block title="MFD, network printer and fax machine usage policy"><paragraph
    title="11.8.3.R.01."

    tags="Communications systems,Governance,MFDs"


><![CDATA[<p>MFDs, network printers and fax machines, are capable of communicating classified information, and are a potential source of information security incidents. It is therefore essential that agencies develop a policy governing their use.</p>]]></paragraph>
<paragraph
    title="11.8.3.C.01."

    tags="Communications systems,Governance,MFDs"


    classification="All Classifications"
    compliance="Must"
    cid="2537"
><![CDATA[<p>Agencies MUST develop a policy governing the use of MFDs, network printers and fax machines,</p>]]></paragraph>
</block>
<block title="Sending fax messages"><paragraph
    title="11.8.4.R.01."

    tags="Communications systems,Technical"


><![CDATA[<p>Once a MFD or fax machine has been connected to cryptographic equipment and used to send a classified fax message it can pose risks if subsequently connected directly to unsecured telecommunications infrastructure or the public switched telephone network (PSTN).&nbsp;For example, if a fax machine fails to send a classified fax message the device will continue attempting to send the fax message even if it has been disconnected from the cryptographic device and connected directly to the public switched telephone network. In such cases the fax machine could then send the classified fax message in the clear causing an information security incident.</p>]]></paragraph>
<paragraph
    title="11.8.4.R.02."

    tags="Communications systems,Technical"


><![CDATA[<p>Non-encrypted communications may be exposed in transmission and, if incorrectly addressed or an incorrect recipient number is entered, may cause a data breach.</p>]]></paragraph>
<paragraph
    title="11.8.4.C.01."

    tags="Communications systems,Technical"


    classification="Top Secret, Secret, Confidential"
    compliance="Must"
    cid="2543"
><![CDATA[<p>Agencies sending classified messages MUST ensure that the message is encrypted to an appropriate level when communicated over unsecured telecommunications infrastructure or the public switched telephone network.</p>]]></paragraph>
<paragraph
    title="11.8.4.C.02."

    tags="Communications systems,Technical"


    classification="Top Secret, Confidential, Secret"
    compliance="Must"
    cid="2545"
><![CDATA[<p>Agencies MUST have separate MFDs or fax machines for sending classified messages and messages classified RESTRICTED and below.</p>]]></paragraph>
</block>
<block title="Receiving fax messages"><paragraph
    title="11.8.5.R.01."

    tags="Communications systems,Technical"


><![CDATA[<p>Whilst the communications path between MFDs and fax machines may be appropriately protected, personnel need to remain cognisant of the need-to-know of the information that is being communicated. As such it is important that fax messages are collected from the receiving MFD or fax machine as soon as possible. Furthermore, if an expected fax message is not received it may indicate that there was a problem with the original transmission or the fax message has been taken by an unauthorised person.</p>]]></paragraph>
<paragraph
    title="11.8.5.C.01."

    tags="Communications systems,Technical"


    classification="All Classifications"
    compliance="Should"
    cid="2562"
><![CDATA[<p>The sender of a fax message SHOULD make arrangements for the receiver to:</p>
<ul>
<li>collect the fax message as soon as possible after it is received; and</li>
<li>notify the sender immediately if the fax message does not arrive when expected.</li>
</ul>]]></paragraph>
</block>
<block title="Connecting MFDs to telephone networks"><paragraph
    title="11.8.6.R.01."

    tags="Communications systems,MFDs,Technical"


><![CDATA[<p>When a MFD is connected to a computer network and a telephone network the device can act as a bridge between the networks. As such the telephone network needs to be accredited to the same classification as the computer network the MFD is connected to.</p>]]></paragraph>
<paragraph
    title="11.8.6.C.01."

    tags="Communications systems,MFDs,Technical"


    classification="Top Secret, Secret, Confidential"
    compliance="Must Not"
    cid="2568"
><![CDATA[<p>Agencies MUST NOT enable a direct connection from a MFD to a telephone network unless the telephone network is accredited to at least the same classification as the computer network to which the device is connected.</p>]]></paragraph>
<paragraph
    title="11.8.6.C.02."

    tags="Communications systems,MFDs,Technical"


    classification="All Classifications"
    compliance="Should Not"
    cid="2570"
><![CDATA[<p>Agencies SHOULD NOT enable a direct connection from a MFD to a telephone network unless the telephone network is accredited to at least the same classification as the computer network to which the device is connected.</p>]]></paragraph>
</block>
<block title="Connecting MFDs to computer networks"><paragraph
    title="11.8.7.R.01."

    tags="Communications systems,MFDs,Technical"


><![CDATA[<p>As network connected MFDs are considered to be devices that reside on a computer network they need to be able to process the same classification of information that the network is capable of processing.</p>]]></paragraph>
<paragraph
    title="11.8.7.C.01."

    tags="Communications systems,MFDs,Technical"


    classification="All Classifications"
    compliance="Must"
    cid="2575"
><![CDATA[<p>Where MFDs connected to computer networks have the ability to communicate via a gateway to another network, agencies MUST ensure that:</p>
<ul>
<li>each MFD applies user identification, authentication and audit functions for all classified information communicated by that device;</li>
<li>these mechanisms are of similar strength to those specified for workstations on that network; and</li>
<li>each gateway can identify and filter the classified information in accordance with the requirements for the export of data through a gateway.</li>
</ul>]]></paragraph>
</block>
<block title="Copying documents on MFDs"><paragraph
    title="11.8.8.R.01."

    tags="Communications systems,MFDs,Technical"


><![CDATA[<p>As networked MFDs are capable of sending scanned or copied documents across a connected network, personnel need to be aware that if they scan or copy documents at a classification higher than that of the network the device is connected to they could be causing a data spill onto the connected network.</p>]]></paragraph>
<paragraph
    title="11.8.8.C.01."

    tags="Communications systems,MFDs,Technical"


    classification="All Classifications"
    compliance="Must Not"
    cid="2578"
><![CDATA[<p>Agencies MUST NOT permit MFDs connected to computer networks to be used to scan or copy classified documents above the classification of the connected network.</p>]]></paragraph>
</block>
<block title="Observing MFD and fax machine use"><paragraph
    title="11.8.9.R.01."

    tags="Communications systems,MFDs,Technical"


><![CDATA[<p><span>Placing MFDs and fax machines in public areas can help reduce the likelihood of any suspicious use going unnoticed.</span></p>]]></paragraph>
<paragraph
    title="11.8.9.C.01."

    tags="Communications systems,MFDs,Technical"


    classification="All Classifications"
    compliance="Should"
    cid="2581"
><![CDATA[<p>Agencies SHOULD ensure that MFDs and fax machines are located in areas where their use can be observed.</p>]]></paragraph>
</block>
<block title="Servicing and Maintenance"><paragraph
    title="11.8.10.R.01."

    tags="Communications systems,Technical"


><![CDATA[<p>Network and MFD printers invariably use hard disk drives, flash drives or other reusable storage which can contain copies of classified information. Any maintenance or servicing should be conducted under supervision or by cleared personnel.</p>]]></paragraph>
<paragraph
    title="11.8.10.R.02."

    tags="Communications systems,Technical"


><![CDATA[<p>Copiers and laser printers may use electrostatic drums as part of the reproduction and printing process. These drums can retain a “memory” of recent documents which can be recovered. Any storage devices or drums replaced during maintenance should follow the prescribed media disposal and destruction processes (See Chapter 13 – Decommissioning and Disposal).</p>]]></paragraph>
<paragraph
    title="11.8.10.R.03."

    tags="Communications systems,Technical"


><![CDATA[<p>Toner cartridges and other components may incorporate a memory chip, often used to track pages numbers and estimate print capacity. These chips have read/write capability and may pose a risk to classified systems. Once chips have been removed, the toner cartridges themselves may be disposed of through supplier recycling or other approved disposal channels.</p>]]></paragraph>
<paragraph
    title="11.8.10.C.01"

    tags="Communications systems,Technical"


    classification="Confidential, Secret, Top Secret"
    compliance="Must"
    cid="2589"
><![CDATA[<p>Any maintenance or servicing MUST be conducted under supervision or by cleared personnel.</p>]]></paragraph>
<paragraph
    title="11.8.10.C.02"

    tags="Communications systems,Technical"


    classification="Secret, Top Secret, Confidential"
    compliance="Must"
    cid="2590"
><![CDATA[<p>Any storage devices, drums or cartridges with memory chips removed during maintenance or servicing MUST be disposed of following the processes prescribed in <a title="Media and IT Equpment management, decommissioning and disposal" href="http://nzism.gcsb.govt.nz/ism-document#Chapter-14678">Chapter 13 - Media and IT equipment Management, Decommissioning and Disposal</a>.</p>]]></paragraph>
<paragraph
    title="11.8.10.C.03"

    tags="Communications systems,Technical"


    classification="Confidential, Secret, Top Secret"
    compliance="Must"
    cid="2591"
><![CDATA[<p>Toner cartridges MUST have the memory chip removed before the cartridge is recycled or otherwise disposed of. The memory chip MUST be disposed of following the processes prescribed in <a title="Media and IT Equpment management, decommissioning and disposal" href="http://nzism.gcsb.govt.nz/ism-document#Chapter-14678">Chapter 13 - Media and IT equipment Management, Decommissioning and Disposal.</a></p>]]></paragraph>
<paragraph
    title="11.8.10.C.04"

    tags="Communications systems,Technical"


    classification="All Classifications"
    compliance="Should"
    cid="2592"
><![CDATA[<p>Any maintenance or servicing SHOULD be conducted under supervision or by cleared personnel.</p>]]></paragraph>
<paragraph
    title="11.8.10.C.05"

    tags="Communications systems,Technical"


    classification="All Classifications"
    compliance="Should"
    cid="2593"
><![CDATA[<p>Any storage devices, drums or cartridges with memory chips removed during maintenance or servicing SHOULD be disposed of following the processes prescribed in&nbsp;<a title="Media and IT Equpment management, decommissioning and disposal" href="http://nzism.gcsb.govt.nz/ism-document#Chapter-14678">Chapter 13 - Media and IT equipment Management, Decommissioning and Disposal</a>.</p>]]></paragraph>
</block>
<block title="USB Devices"><paragraph
    title="11.8.11.R.01."

    tags="Communications systems,Technical"


><![CDATA[<p>MFDs may also be equipped with USB ports for maintenance and software updates. It is possible to copy data from installed storage devices to USB devices. Any use of USB capabilities must be carefully managed.</p>]]></paragraph>
<paragraph
    title="11.8.11.C.01"

    tags="Communications systems,Technical"


    classification="Top Secret, Confidential, Secret"
    compliance="Must"
    cid="2596"
><![CDATA[<p>The use of any USB capability MUST be conducted under supervision or by cleared personnel.</p>]]></paragraph>
<paragraph
    title="11.8.11.C-02"

    tags="Communications systems,Technical"


    classification="All Classifications"
    compliance="Should"
    cid="2597"
><![CDATA[<p>The use of any USB capability SHOULD be conducted under supervision or by cleared personnel.</p>]]></paragraph>
</block>
<block title="Decommissioning and Disposal"><paragraph
    title="11.8.12.R.01."

    tags="Communications systems,Technical,Disposal"


><![CDATA[<p>The use of storage media and the characteristics of electrostatic drums allow the recovery of information from such devices and components. To protect the information, prescribed disposal procedures should be followed.</p>]]></paragraph>
<paragraph
    title="11.8.12.R.02."

    tags="Communications systems,Technical,Disposal"


><![CDATA[<p>The use of storage media and the characteristics of electrostatic drums allow the recovery of information from such devices and components. To protect the information, prescribed disposal procedures should be followed.</p>]]></paragraph>
<paragraph
    title="11.8.12.C.01"

    tags="Communications systems,Technical,Disposal"


    classification="Top Secret, Confidential, Secret"
    compliance="Must"
    cid="2604"
><![CDATA[<p>Any storage devices, drums, cartridge memory chips or other components that may contain data or copies of documents MUST be disposed of following the processes prescribed in&nbsp;<a title="Media and IT Equpment management, decommissioning and disposal" href="http://nzism.gcsb.govt.nz/ism-document#Chapter-14678">Chapter 13 - Media and IT equipment Management, Decommissioning and Disposal</a>.</p>]]></paragraph>
<paragraph
    title="11.8.12.C.02"

    tags="Communications systems,Technical,Disposal"


    classification="All Classifications"
    compliance="Should"
    cid="2606"
><![CDATA[<p>Any storage devices, drums, cartridge memory chips or other components that may contain data or copies of documents SHOULD be disposed of following the processes prescribed in&nbsp;<a title="Media and IT Equpment management, decommissioning and disposal" href="http://nzism.gcsb.govt.nz/ism-document#Chapter-14678">Chapter 13 - Media and IT equipment Management, Decommissioning and Disposal</a>.</p>]]></paragraph>
</block>
<block title="Logging multifunction device use"><paragraph
    title="11.8.13.R.01."

    tags="Communications systems,Event Logging"


><![CDATA[<p>Centrally logging and analysing MFD events, which may include metadata and shadow copies of documents printed, scanned or copied by users, can assist in monitoring the security posture of systems, detecting malicious behaviour, and contributing to investigations following cyber security incidents. Logs are stored in a central system, such as a security information and event management tool or central database and can only be accessed or modified by authorised and authenticated users. Logs are stored for a duration informed by risk or regulatory guidelines.</p>]]></paragraph>
<paragraph
    title="11.8.13.C.01."

    tags="Communications systems,Event Logging"


    classification="Top Secret, Secret, Confidential"
    compliance="Should"
    cid="7537"
><![CDATA[<p>Use of MFDs for printing, scanning, and copying purposes SHOULD be centrally logged.</p>]]></paragraph>
</block>
</subsection>
</section>
