HP LaserJet Enterprise MFP M725 HP Commercial LaserJet Printers and MFPs - Ima - Page 12

Elevation of Privilege

Page 12 highlights

 Causing interference with network communication to the MFP  Changing the network location of the MFP  Causing an error state that interrupts service  Changing access configurations Here are some methods of minimizing opportunities for denial of service on an MFP:  Lock the control panel.  Lock EWS configuration settings.  Close unused ports and protocols.  Disable controls such as the Job Cancel button and the Go button.  Enable the resume feature to allow the MFP to resume operations after an error state.  Configure Job Timeout.  Control physical access to the MFP.  Lock physical access to removable hardware. Elevation of Privilege Elevation of privilege is any method of upgrading authorized access to include unauthorized access. This can be any of the following:  Non-administrators changing settings to get administrator privileges  Unauthorized use of management software to provide access for other unauthorized users  Using management software to bypass job accounting functions Here are some methods of minimizing opportunities for elevation of privilege:  Configure the administrator (device) password.  Configure SNMPv3 and HTTPS.  Lock the control panel. Chapter 2 HP LaserJet and Color LaserJet MFP Security Checklist 8

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93

Chapter 2
HP LaserJet and Color LaserJet MFP Security Checklist
8
Causing interference with network communication to the MFP
Changing the network location of the MFP
Causing an error state that interrupts service
Changing access configurations
Here are some methods of minimizing opportunities for denial of service on an MFP:
Lock the control panel.
Lock EWS configuration settings.
Close unused ports and protocols.
Disable controls such as the Job Cancel button and the Go button.
Enable the resume feature to allow the MFP to resume operations after an error state.
Configure Job Timeout.
Control physical access to the MFP.
Lock physical access to removable hardware.
Elevation of Privilege
Elevation of privilege is any method of upgrading authorized access to include unauthorized
access. This can be any of the following:
Non-administrators changing settings to get administrator privileges
Unauthorized use of management software to provide access for other unauthorized users
Using management software to bypass job accounting functions
Here are some methods of minimizing opportunities for elevation of privilege:
Configure the administrator (device) password.
Configure SNMPv3 and HTTPS.
Lock the control panel.