Secure Installation and Operation of Your WorkCentre™ 5135/5150
Purpose and Audience
This
document provides information on the secure installation and operation of a WorkCentre™ 5135/5150 Multifunction
System. All customers, but particularly those concerned with secure installation and operation of these machines, should follow
these guidelines.
Overview
This document lists some important customer information and guidelines that will ensure that your WorkCentre™ 5135/5150
Multifunction System is operated and maintained in a secure manner.
Background
The WorkCentre™ 5135/5150 Multifunction System is currently undergoing Common Criteria evaluation. The information
provided here is consistent with the security functional claims made in the Security Target. Upon completion of the evaluation,
the Security Target will be available from the Common Criteria Certified Product website
(
http://www.commoncriteriaportal.org/products.html
) list of evaluated products or from your Xerox representative.
Secure Evaluated Configuration Installation, Setup and Operation
Please follow the guidelines below for secure installation, setup and operation of the evaluated configuration for a
WorkCentre™ 5135/5150 Multifunction System:
1.
The security functions in the evaluated configuration of the WorkCentre™ 5135/5150 that should be set up by the System
Administrator are:
•
Immediate Image Overwrite
•
On Demand Image Overwrite
•
Disk Encryption
•
IP Filtering
•
Audit Log
•
SSL (for protection of management data)
•
Trusted Certificate Authorities
•
Authentication and Authorization
Follow the instructions located on the SA CD
1
in the
Reference
Æ
Security
tabs/buttons to set up these security functions
except as noted in the items below.
2.
The following services of the WorkCentre™ 5135/5150 are also considered part of the evaluated configuration and should be
enabled when needed by the System Administrator - Copy, Embedded Fax, Scan to E-mail, Network Scanning, Saved Jobs for
Reprint, Reprint Saved Jobs, and ID Card Copy.
3.
Secure acceptance of the WorkCentre™ 5135/5150, once device delivery and installation is completed, should be done by:
•
Printing out a Configuration Report by following the instructions located on the SA CD
1
in the
Reference
Æ
Reports
Æ
Configuration
tabs.
•
Comparing the software/firmware versions listed on the Configuration Report with the Evaluated Software/Firmware
versions listed in Table 2 of the Xerox WorkCentre™ 5135/5150 Multifunction Systems Security Target, Version 1.0 and
make sure that they are the same in all cases.
4.
Follow the instructions located on the SA CD
1
in the
Reference
Æ
Security
Æ
Authentication and Authorization
Æ
Authentication Configuration
tabs/buttons to set up an Authentication Server. Follow the instructions located on the SA CD
1
in
the
Reference
Æ
Security
Æ
Authentication and Authorization
Æ
Xerox Common Access Card
tabs/buttons to set up user
authentication via a Common Access Card.
5.
For customers concerned about document files on the network controller hard disk drive or Embedded Fax card memory, the
Image Overwrite Security (IOS) option containing the Immediate Image Overwrite and On Demand Image Overwrite security
features, which comes installed on the WorkCentre™ 5135/5150 Multifunction System, must be properly configured and
enabled. Please follow the applicable instructions in the
Reference
Æ
Security
Æ
Image Overwrite Security
tabs/buttons in the
System Administration (SA) CD
1
for proper enablement of Immediate Image Overwrite and On Demand Image Overwrite.
1
(WorkCentre™ 5135/5150) System Administration CD1, 538E11432