Page 2 - White Paper: Canon imageRUNNER ADVANCE Security
2 White Paper: Canon imageRUNNER ADVANCE Security Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . 3 2. Device Security. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . 5 3. Information Security . . . . ...
Page 4 - Section 1 — Introduction; — Security Market Overview; Device Security
4 White Paper: Canon imageRUNNER ADVANCE Security Section 1 — Introduction 1.1 — Security Market Overview In today’s digital world, risks to networks and devices come in more forms and from more directions than ever before. From identity theft and intellectual property loss to infection by viruses a...
Page 5 - — imageRUNNER ADVANCE Controller Security; Device-Based Authentication; Department ID Mode; Domain Authentication + Local Device Authentication
5 White Paper: Canon imageRUNNER ADVANCE Security Section 2 — Device Security 2.1 — imageRUNNER ADVANCE Controller Security The imageRUNNER ADVANCE series is built upon a new platform that provides powerful enhancements to security and productivity. The new architecture centers on a new operating sy...
Page 6 - Section 2 — Device Security; Card-Based Authentication; uniFLOW Card Authentication
6 White Paper: Canon imageRUNNER ADVANCE Security Section 2 — Device Security When used in Domain Authentication mode, a user must successfully authenticate using valid credentials on the system’s control panel, Remote UI utility, or web browser when accessed via a network prior to gaining access to...
Page 7 - Control Cards/Card Reader System; – Access Control; Password-Protected System Settings
7 White Paper: Canon imageRUNNER ADVANCE Security System Manager Screen Store ID and Password Screen Section 2 — Device Security Authorized Send for CAC/PIV supports two-factor authentication by prompting users to insert their card into the device’s card reader and requiring them to enter their PIN....
Page 8 - Access Management System; Privileges by Access Level; Device Function
8 White Paper: Canon imageRUNNER ADVANCE Security Section 2 — Device Security Access Management System The Access Management System, which is standard on imageRUNNER ADVANCE systems, can be used to tightly control access to device functionality. Restrictions can be assigned to users and groups, to r...
Page 9 - Function Level Authentication; Scan and Send Security; Address Book Password
9 White Paper: Canon imageRUNNER ADVANCE Security Section 2 — Device Security When the Access Management System has been enabled, users must log in to the device using SSO user authentication. Access Management System supports authentication through local device authentication as well as Active Dire...
Page 10 - Access Code for Address Book; Entries in the Address Book; Print Driver Security Features; Print Job Accounting
10 White Paper: Canon imageRUNNER ADVANCE Security Section 2 — Device Security Access Code for Address Book End-users will also have the capacity to place an access number code on addresses in the Address Book. When registering an address, users can then enter an Access Number to restrict the displa...
Page 11 - USB Block; – Third Party MEAP Application and Development
11 White Paper: Canon imageRUNNER ADVANCE Security Section 2 — Device Security USB Block USB Block allows the System Administrator to help protect the imageRUNNER ADVANCE systems against unauthorized access through the built-in USB interface. Access to the device’s USB interface for desktop access a...
Page 12 - Section 3 — Information Security; – Document Security; Secure Printing; Secured Print / Encrypted Secured Print*; uniFLOW Secure Print
12 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security Protecting your organization’s confidential information is a mission that Canon takes seriously. From your documents, faxes and e-mails to the underlying data on the internal hard disk drive and in memory, Canon has ...
Page 15 - Document Storage Space Protection; Mail Box Security; Activate authentication and enable Personal Space
15 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security Document Storage Space Protection Mail Box Security Each imageRUNNER ADVANCE system ships standard with Mail Boxes for storage of scanned and printed data. Mail Box security is provided by the ability to designate a ...
Page 16 - Other Document Security Capabilities; Watermark / Secure Watermark
16 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security To prevent the storage of executable files that may contain viruses and other malicious code, system administrators can restrict the types of documents that can be saved to only printable formats, such as PDF, TIFF, ...
Page 18 - Copy Set Numbering; Rights Management; Document Scan Lock & Trace
18 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security The Device Signature PDF and the Device Signature XPS mode use the device signature certificate and key pair inside the machine to add a digital signature to the document, which enables the recipient to verify the de...
Page 19 - Data at Rest; HDD and RAM Data Protection; iR File System
19 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security System administrators can choose to force all scan and copy jobs to apply Document Scan Lock & Tracking code onto each print job, as well as choose whether to allow all or prohibit all copy, scan, send and fax jo...
Page 20 - HDD Data Encryption Kit
20 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security Standard HDD Format* Best practices, and often company policies, usually recommend that systems be completely wiped by the system administrator prior to the device being reallocated to a new location or prior to the ...
Page 21 - Once with null data,; Timing of Overwrite; Set daily, weekly and monthly schedule for overwriting HDD data
21 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security HDD Data Erase Kit The optional HDD Data Erase Kit, which is now Standard on all Next Generation imageRUNNER ADVANCE Systems, enables system administrators to configure their imageRUNNER ADVANCE to overwrite the inte...
Page 22 - Group Sort
22 White Paper: Canon imageRUNNER ADVANCE Security 1. Copy/Print Mode: a. Group Sort When a user programs a job to be sorted into group sets with no finishing specified, the page data would be overwritten every time a ‘set’ is complete. b. Collate Sort When a user programs a job to be sorted into co...
Page 23 - Performance Impact Using the HDD Data Erase Kit; Fax Activity management report
23 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security 3. Send/Scan Job: b. Send/Scan Data When a user sends or scans a job to another destination, all page data will be deleted or overwritten immediately after the entire job has been sent. c. Fax/I-Fax Data When the “Fa...
Page 24 - HDD Lock; Data in Transit; Encrypted Secured Print; Super G3 Fax Board and Multi Line Fax Board
24 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security Workflow Composer Canon imageRUNNER ADVANCE Workflow Composer enables users and administrators to create custom workflows that automate redundant tasks and provide integration with back-end systems via connectors. Ad...
Page 25 - Super G3 Fax Board Communication Mechanism; Other Fax Features; Fax Forwarding / Mailbox Fax Forwarding
25 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security Super G3 Fax Board Communication Mechanism The modem on the Super G3 Fax Boards does not have Data Modem capability, but only Fax Modem capability. As a result, TCP/IP communication through the phone line is impossib...
Page 26 - Fax Storage Space; Fax Mail Box and Advanced Box Fax Security
26 White Paper: Canon imageRUNNER ADVANCE Security Section 3 — Information Security Fax Storage Space Fax Mail Box and Advanced Box Fax Security Incoming faxes on imageRUNNER ADVANCE systems can be automatically routed to a designated Mail Box or Advanced Box, which can be password-protected to prev...
Page 27 - Section 4 — Network Security; – Network and Print Security (Canon Network Printer Kit Only); Enabling/Disabling Protocols/Applications; Name
27 White Paper: Canon imageRUNNER ADVANCE Security Section 4 — Network Security 4.1 – Network and Print Security (Canon Network Printer Kit Only) Canon imageRUNNER ADVANCE systems include a number of highly configurable network security features that assist in securing information when the optional ...
Page 28 - SSL Encryption
28 White Paper: Canon imageRUNNER ADVANCE Security Section 4 — Network Security IP Address and Port Filtering Using the RX/Print Settings function, the System Manager can limit network access to the device to specific IP addresses or ranges for printing and Settings/Browsing. Up to eight individual ...
Page 29 - Authentication and Encryption Method:; Key Exchange Protocol; RSA algorithm; Wireless LAN
29 White Paper: Canon imageRUNNER ADVANCE Security Section 4 — Network Security Authentication and Encryption Method: One of the following methods must be set for the device. AH (Authentication Header) A protocol for certifying authentication by detecting modifications to the communicated data, in...
Page 30 - Data with a virus attached in the e-mail:
30 White Paper: Canon imageRUNNER ADVANCE Security establishes a point-to-point connection only if authentication is successful. The Extensible Authentication Protocol (EAP) is attached to both wired and wireless LAN networks, allowing multiple authentication methods such as cards and one-time passw...
Page 31 - – Mail Server Security; SMTP Authentication
31 White Paper: Canon imageRUNNER ADVANCE Security mail for printing and transfer. The e-mail text data is comprised of character strings. If binary data such as data with a virus is used in the e-mail text, the data will be damaged and data with a virus will be discarded. Even if the data with a vi...
Page 32 - Section 5 — Security Monitoring & Management Tools; – imageWARE Enterprise Management Console
32 White Paper: Canon imageRUNNER ADVANCE Security Section 5 — Security Monitoring & Management Tools Canon provides a number of tools to help organizations enforce their internal company policies and meet regulatory requirements. Whether a single imageRUNNER ADVANCE system is deployed, or a fle...
Page 33 - Section 6 — Logging & Auditing; LOCK; – Canon imageWARE Accounting Manager Plug-in; Track by paper type, single and double-sided output or N-Up output
33 White Paper: Canon imageRUNNER ADVANCE Security Section 6 — Logging & Auditing Few security procedures can completely prevent the intentional leak of confidential information while maintaining high productivity, but if an occurrence does happen it is important to be able to trace it to the so...
Page 34 - – Canon imageRUNNER ADVANCE Tracker
34 White Paper: Canon imageRUNNER ADVANCE Security Track by device Track by Individual, group or department Track by black-and-white or color copy/print jobs Multi-tiered billing codes for charge back purposes Analyze department/device workload Enforce usage limits Export reports Inp...
Page 35 - Section 7 — Canon Solutions & Regulatory Requirements; – Common Criteria
35 White Paper: Canon imageRUNNER ADVANCE Security Section 7 — Canon Solutions & Regulatory Requirements Canon is dedicated to providing the most secure multifunctional printers available on the market today. Many of our products meet or exceed the requirements of government agencies and private...
Page 36 - IEEE 2600 License Certificate; Authorized Send CAC/PIV
36 White Paper: Canon imageRUNNER ADVANCE Security Section 7 — Canon Solutions & Regulatory Requirements information assurance. IEEE 2600.1 defines requirement specifications for office use as well as government agencies where high level of assurance is required. The IEEE2600.1 Common Criteria c...
Page 37 - Section 8 — Conclusion
37 White Paper: Canon imageRUNNER ADVANCE Security Section 8 — Conclusion Since initially introduced, the highly successful Canon imageRUNNER series of devices have rapidly grown in both the breadth and depth of features and functions. With each release, these devices have become increasingly integr...
Page 38 - Section 9 — Addendum; – Canon Security Recommendations Quick Reference
38 White Paper: Canon imageRUNNER ADVANCE Security Section 9 — Addendum 9.1 – Canon Security Recommendations Quick Reference Each customer’s needs are different, and while the security of corporate data is ultimately the responsibility of the customer, the security technologies outlined below may he...
Page 39 - Fun
39 White Paper: Canon imageRUNNER ADVANCE Security Section 9 — Addendum 9.2 – Canon imageRUNNER ADVANCE Security Features Supported Device List Security Features iR-ADV C9000PRO/ C7000/C5000/ C2000 Series iR-ADV 8000/6000/ 4000 Series iR-ADV C5200/C2200, 6200/8200 Series Device Based Authentication ...
Page 40 - – IEEE 2600.1 CC Functional Requirements
40 White Paper: Canon imageRUNNER ADVANCE Security 9.3 – IEEE 2600.1 CC Functional Requirements 9.4 – IEEE 2600.1 CC Settings/Registration Items Preferences
Page 41 - Management Settings
41 White Paper: Canon imageRUNNER ADVANCE Security 9.4 – IEEE 2600.1 CC Settings/Registration Items Function Settings Management Settings *1 Same as the setting at the time of shipment *2 A general user cannot operate the following functions when [ON] is selected for [Restrict Auto Reset Time]. - [A...
Page 42 - Regulatory Disclaimer:
White Paper: Canon imageRUNNER ADVANCE Security The information provided in this document is the most current information available at the time of its creation. Canon hereby expressly disclaims all warranties of any kind, express or implied, statutory or non-statutory, in relation to the information...