HP DesignJet Z5400 Security Features - Page 74

Device protection

Page 74 highlights

HP DesignJet Printer Series Security Settings Device protection related BIOS BIOS The BIOS (basic input/output system) is the program used to get the printer system started after it is turned on. HP Sure Start It validates the integrity of the BIOS at every boot cycle. If a compromised version is discovered, the device reboots using a safe, "golden copy" of the BIOS. UEFI Secure Boot Method to prevent the loading of unauthorized operating systems during the system startup. Based on the UEFI Forum specification (www.uefi.org). CONFIGURATION Disable ports and protocols It allows the administrator to select which protocols and services are enabled. Restricting the enabled protocols to only those that are actually needed means the administrator can reduce the risk of vulnerability. Instant-On Security Devices supporting Instant-On Security features can be automatically added into the Security Manager as soon as they are connected to the network or from reset without any intervention. Instant-On Security immediately configures the device to be compliant with the corporate security policy. SNMPv3 SNMP is a protocol to get and configure printer information. SNMPv3 is the encrypted version. When enabled, only the client applications knowing the keys will be able to access the printer using this protocol. FIRMWARE HP signed firmware packages Firmware packages are digitally signed by the HP Code Signing group. The printer uses the public key of this group to verify the signature before installing the new firmware, thus ensuring that only legitimate firmware from HP can be installed in the printer. Only forward firmware security upgrades Behavior of the firmware that prevents installation of older firmware releases that have known security vulnerabilities. RD only file system Solution to guarantee that the firmware cannot be altered. It is based on configuring the filesystem where the printer firmware is located as a read only partition. 74

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80

HP DesignJet Printer Series
Security Settings
74
Device protection
related
BIOS
BIOS
The BIOS (basic input/output system) is the program used to get the printer system started after it is turned on.
HP Sure Start
It validates the integrity of the BIOS at every boot cycle. If a compromised version is discovered, the device
reboots using a s
afe, “golden copy” of the BIOS.
UEFI Secure Boot
Method to prevent the loading of unauthorized operating systems during the system startup. Based on the UEFI
Forum specification (www.uefi.org).
CONFIGURATION
Disable ports and protocols
It allows the administrator to select which protocols and services are enabled. Restricting the enabled protocols
to only those that are actually needed means the administrator can reduce the risk of vulnerability.
Instant-On Security
Devices supporting
Instant-On Security
features can be automatically added into the Security Manager as soon
as they are connected to the network or from reset without any intervention. Instant-On Security immediately
configures the device to be compliant with the corporate security policy.
SNMPv3
SNMP is a protocol to get and configure printer information. SNMPv3 is the encrypted version. When enabled,
only the client applications knowing the keys will be able to access the printer using this protocol.
FIRMWARE
HP signed firmware packages
Firmware packages are digitally signed by the HP Code Signing group. The printer uses the public key of this
group to verify the signature before installing the new firmware, thus ensuring that only legitimate firmware
from HP can be installed in the printer.
Only forward firmware security upgrades
Behavior of the firmware that prevents installation of older firmware releases that have known security
vulnerabilities.
RD only file system
Solution to guarantee that the firmware cannot be altered. It is based on configuring the filesystem where the
printer firmware is located as a read only partition.