Lexmark MS517 Embedded Web Server--Security: Administrator s Guide - Page 74

Installing the minimum Common Criteria configuration, Configuring disk wiping

Page 74 highlights

Appendix 74 Installing the minimum Common Criteria configuration Configuring disk wiping Disk wiping removes residual confidential material from the printer. It uses random data patterns to securely overwrite files stored on the hard disk that have been marked for deletion. Multiple‑pass wiping is compliant with the DoD 5220.22‑M standard for securely erasing data from a hard disk. 1 Navigate to the screen menu, and then touch Security > Disk Wiping. 2 Make sure that Wiping Mode to Auto. 3 Set Automatic Method to Multi‑pass. 4 Touch Submit. Enabling the backup password (optional) Note: Using a backup password is strongly discouraged because it can degrade the overall security of your printer. For more information on how to configure a backup password security, see "Setting a backup password" on page 29. Creating user accounts To create accounts for use with the evaluated configuration, assign user IDs, password, and groups to users. When configuring security templates, select one or more of these groups, and apply a security template to each device. Step 1: Defining groups Create either two or four groups depending on whether there is a need to grant access to some administrative functions while restricting others with names and functions. For more information on how to set up user groups, see "Setting up internal accounts" on page 11. Scenario 1: Using two groups Select Administrator_Only Authenticated_Users For Administrators allowed to access all device functions • Administrators • Non‑administrators (all other users) Scenario 2: Using multiple groups Select Administrator_Only Administrator_Reports For Administrators allowed to access all device functions • Administrators allowed to access all device functions • Administrators allowed to use device functions and access the Reports menu

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93

Installing the minimum Common Criteria configuration
Configuring disk wiping
Disk wiping removes residual confidential material from the printer. It uses random data patterns to securely
overwrite files stored on the hard disk that have been marked for deletion. Multiple
pass wiping is compliant
with the DoD 5220.22
M standard for securely erasing data from a hard disk.
1
Navigate to the screen menu, and then touch
Security
>
Disk Wiping
.
2
Make sure that Wiping Mode to
Auto
.
3
Set Automatic Method to
Multi
pass
.
4
Touch
Submit
.
Enabling the backup password (optional)
Note:
Using a backup password is strongly discouraged because it can degrade the overall security of your
printer.
For more information on how to configure a backup password security, see
“Setting a backup password” on
page
29
.
Creating user accounts
To create accounts for use with the evaluated configuration, assign user IDs, password, and groups to users.
When configuring security templates, select one or more of these groups, and apply a security template to each
device.
Step 1: Defining groups
Create either two or four groups depending on whether there is a need to grant access to some
administrative functions while restricting others with names and functions. For more information on how to
set up user groups, see
“Setting up internal accounts” on page
11
.
Scenario 1: Using two groups
Select
For
Administrator_Only
Administrators allowed to access all device functions
Authenticated_Users
Administrators
Non
administrators (all other users)
Scenario 2: Using multiple groups
Select
For
Administrator_Only
Administrators allowed to access all device functions
Administrator_Reports
Administrators allowed to access all device functions
Administrators allowed to use device functions and access the
Reports menu
Appendix
74