SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Project Management

Plugging the MFP security gap

Plugging the MFP security gap

By:  Mason Olds  On: 31 Aug 2006 For: CIO Canada Creator

When developing IT security plans, companies can easily overlook one seemingly harmless but vulnerable piece of equipment: The multifunction printing device. Don’t let MFPs become your achilles heel.

Responding to an IT security breach undoubtedly ranks among a CIO’s worst nightmares. The thought of your company’s lost customer or financial data making the headlines is enough to disturb anyone’s sleep. This is why more organizations are turning to CIOs and CSOs for answers on why these failures occur and, more importantly, how to prevent them.

Industry experts agree that the level and extent of security threats today are on the rise. A report commissioned by McAfee (July 2005) states that cybercrime cost organizations US$400 billion in 2004, with 2,000 new threats emerging each month compared to 300 threats two years prior to that. It’s no surprise to see businesses stepping up their efforts to secure their networks. An ounce of prevention can mean an invaluable amount of cure.

When developing IT security plans, however, many companies can easily overlook one piece of equipment – the multifunction printing (MFP) device. A common fixture in many office environments, MFPs can print, copy, scan and fax documents. While these all-in-one devices increase productivity by being connected to the network, their connectivity is precisely what makes them potentially vulnerable to attack. Nonetheless, securing MFPs is simple once it’s understood where to focus efforts.

Here are the five areas where documents generated by MFPs are most at risk:

1. From the desktop: A file can be seized en route from the desktop to the server and used either in its existing form or modified and even exploited externally.

2. At the server: Jobs sent to the MFP for printing typically sit unprotected on the server queue. At this stage, an internal hacker can pause the printing queue, copy a file, and restart the queue without noticeably disrupting the system.

3. Between the server and the MFP: This is another point where documents are travelling unprotected – while on the way to the MFP device, information is fully exposed to anyone who can tap into the network.

4. On the MFP: All information sent to the MFP is stored in the device’s hard drive. MFP hard drives can typically store about as much information as a PC hard drive.

5. Left in the output tray: In most office environments, it is common to pick up printed materials that belong to a co-worker. There are also cases when printed documents are left or forgotten at the printer, leaving information open and available to anyone with access to the machine.

Based on these potential points of access, it is important to evaluate your current MFP solution to determine how to incorporate these devices into your security strategy. Consider the following when evaluating your current MFP environment:

What security features does the MFP offer? There are several ways to increase security levels at each stage of printing a document. MFPs that include 128bit SSL (Secure Sockets Layer) encryption, for instance, provide added security as encrypted documents cannot easily be deciphered. Some MFPs provide the ability to program the device with Media Access Control (MAC) addresses or IP filtering so that the device will only communicate with recognized computers specified by the IT department. Any other computer attempting to communicate with the MFP would be refused access.


Sign up for our Newsletters
Tags: computers












Print |  Views: 1316   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mason Olds Mason Olds is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.
blog comments powered by Disqus