Xerox ColorQube 9201 Secure Installation And Operation - Page 2

Browse online or download pdf Secure Installation And Operation for All in One Printer Xerox ColorQube 9201. Xerox ColorQube 9201 12 pages. Mfp
Also for Xerox ColorQube 9201: Install And Operation Instructions (14 pages), Evaluator Manual (28 pages), Quick User Manual (38 pages), Quick Manual (8 pages), Quick Manual (16 pages), Secure Installation And Operation (12 pages), How To Make A Copy (9 pages)

Xerox ColorQube 9201 Secure Installation And Operation
Secure Installation and Operation of Your ColorQube™
9201/9202/9203
Purpose and Audience
This document provides information on the secure installation and operation of a ColorQube™ 9201/9202/9203 Multifunction
System. All customers, but particularly those concerned with secure installation and operation of these machines, should follow
these guidelines.
Overview
This document lists some important customer information and guidelines that will ensure that your ColorQube
9201/9202/9203 Multifunction System is operated and maintained in a secure manner.
Background
The ColorQube 9201/9202/9203 Multifunction System is currently undergoing Common Criteria evaluation. The information
provided here is consistent with the security functional claims made in the Security Target. Upon completion of the evaluation,
the
Security
Target
(http://www.commoncriteriaportal.org/products.html) list of evaluated products, from the Xerox security website
(http://www.xerox.com/information-security/common-criteria-certified/enus.html ), or from your Xerox representative.
1. Please follow the guidelines below for secure installation, setup and operation of the evaluated configuration
ColorQube 9201/9202/9203 Multifunction System:
a). The security functions in the evaluated configuration that should be set up by the System Administrator are:
Immediate Image Overwrite
On Demand Image Overwrite
Disk Encryption
IP Filtering
Audit Log
SSL (for protection of management data)
IPSec
SNMP v3
Trusted Certificate Authorities
Local, Remote or CAC/PIV Authentication
Local Authorization and Personalization
802.1x Device Authentication
Session Inactivity Timeout
System Administrator login is required when accessing the security features via the Web User Interface (Web UI) or when
implementing the guidelines and recommendations specified in this document. To log in to the Web UI as an authenticated
System Administrator, follow the instructions under "CentreWare Internet Services" located on page 2-6 in the System
Administration Guide (SAG)
To log in to the Local User Interface (Local UI) as an authenticated System Administrator, follow the "Administrator Access"
instructions located on page 2-4 in the SAG.
Follow the instructions located in the SAG in Chapter 8, Security to set up these security functions except as noted in the
items below. Note that whenever the SAG requires that the System Administrator provide an IPv4 address, IPv6 address or
port number the values should be those that pertain to the particular device being configured.
b). The following services are also considered part of the evaluated configuration and should be enabled when needed by the
System Administrator - Copy, Embedded Fax, Scan to E-mail, Workflow Scanning, Scan to Mailbox and Internet Fax.
c). Secure acceptance of a ColorQube 9201/9202/9203, once device delivery and installation is completed, should be done by:
Printing out a Configuration Report by following the "How to Print a Configuration Report" instructions located on page
3-2 of the SAG.
Comparing the software/firmware versions listed on the Configuration Report with the Evaluated Software/Firmware
versions listed in Table 2 of the Xerox ColorQube™ 9201/9202/9203 Multifunction Systems Security Target, Version 1.0
and make sure that they are the same in all cases.
d). Change the Administrator password as soon as possible. Reset the Tools password periodically.
1
The term "evaluated configuration" will be used throughout this document to refer to the configuration of the ColorQube™ 9201/9202/9203
Multifunction System that is currently undergoing Common Criteria evaluation.
2
ColorQube™ 9201/9202/9203 System Administration Guide, Document Version : 1.0 (05/09)
will
be
available
2
.
from
the
Common
Criteria
Certified
Product
website
1
for a