Lexmark C4342 Security White Paper - Page 60

ISO 27001 – Information Security Management System Certification, ISO 20243 – Supply Chain

Page 60 highlights

Security Standards 60 The FIPS 140 Publication Series is issued by the National Institute of Standards and Technology (NIST) to outline the requirements and standards for cryptographic modules which include both hardware and software components that are used by departments and agencies of the United States federal government. The FIPS 140 standard is an outline of requirements that can be used to provide the necessary conditions to secure information, but should not be, nor is designed to be, a guarantee of information security. The requirements covered within the FIPS 140 publication are documented cryptographic modules and, in some cases, source code around the module. Benefits • Third-party validation assures customers that algorithm and/or module meets the requirement as outlined by FIPS. • Buffered data stored in a device hard drive is secured through a FIPS standard protection mechanism. Details Lexmark has also completed a FIPS 140-2 Cryptographic Algorithm Validation Program (CAVP) on the Lexmark devices. This validation provides further assurance of the security of user data while in transit and at rest on Common Criteria-validated devices. CAVP allows for independent validation of the correct implementation of cryptographic algorithms that are used within Lexmark devices. On current and future devices, Lexmark will not only validate the algorithm used to secure information on the device, but also to validate the cryptographic module through NIST's Cryptographic Module Validation Program (CMVP). CMVP validates the use of cryptographic modules as outlined in FIPS 140-2 for the encryption of all data that has a classification of Sensitive But Unclassified (SBU) or above. ISO 27001 - Information Security Management System Certification Overview Lexmark has obtained the ISO 27001 certification for its worldwide Managed Print Services, Predictive Services and Cloud Configurations Services. ISO 27001 is an information security management system (ISMS) international standard that provides a comprehensive set of requirements for maintaining confidentiality, integrity and availability of data. ISO 20243 - Supply Chain Certification Overview In addition to potential attack vectors, your supply chain is a possible area of opportunity for a security breach. Across Lexmark's supply chain, employees and supply partners operate in full compliance with local laws and regulations. We strictly adhere to specifications ensuring that products and parts designed for the device are the same that are delivered. This eliminates the possible introduction of rogue chips or other nefarious elements that are not specified in the original design. In fact, Lexmark is the first print vendor with an ISO 20243 supply chain security certification for the entire printing device, including supplies.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64

The FIPS 140 Publication Series is issued by the National Institute of Standards and Technology (NIST) to outline
the requirements and standards for cryptographic modules which include both hardware and software
components that are used by departments and agencies of the United States federal government. The FIPS
140 standard is an outline of requirements that can be used to provide the necessary conditions to secure
information, but should not be, nor is designed to be, a guarantee of information security. The requirements
covered within the FIPS 140 publication are documented cryptographic modules and, in some cases, source
code around the module.
Benefits
Third-party validation assures customers that algorithm and/or module meets the requirement as outlined
by FIPS.
Buffered data stored in a device hard drive is secured through a FIPS standard protection mechanism.
Details
Lexmark has also completed a FIPS 140-2 Cryptographic Algorithm Validation Program (CAVP) on the Lexmark
devices. This validation provides further assurance of the security of user data while in transit and at rest on
Common Criteria–validated devices. CAVP allows for independent validation of the correct implementation of
cryptographic algorithms that are used within Lexmark devices.
On current and future devices, Lexmark will not only validate the algorithm used to secure information on the
device, but also to validate the cryptographic module through NIST’s Cryptographic Module Validation Program
(CMVP). CMVP validates the use of cryptographic modules as outlined in FIPS 140-2 for the encryption of all
data that has a classification of Sensitive But Unclassified (SBU) or above.
ISO 27001 – Information Security Management System
Certification
Overview
Lexmark has obtained the ISO 27001 certification for its worldwide Managed Print Services, Predictive Services
and Cloud Configurations Services. ISO 27001 is an information security management system (ISMS)
international standard that provides a comprehensive set of requirements for maintaining confidentiality,
integrity and availability of data.
ISO 20243 – Supply Chain Certification
Overview
In addition to potential attack vectors, your supply chain is a possible area of opportunity for a security breach.
Across Lexmark’s supply chain, employees and supply partners operate in full compliance with local laws and
regulations. We strictly adhere to specifications ensuring that products and parts designed for the device are
the same that are delivered. This eliminates the possible introduction of rogue chips or other nefarious elements
that are not specified in the original design. In fact, Lexmark is the first print vendor with an ISO 20243 supply
chain security certification for the entire printing device, including supplies.
Security Standards
60