Page 2 - White Paper: Canon imageRUNNER ADVANCE Security; Table of Contents
2 White Paper: Canon imageRUNNER ADVANCE Security 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 2. Device Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 3. Information Security . . . . . . . . . . . ....
Page 3 - Section 1 — Introduction
3 White Paper: Canon imageRUNNER ADVANCE Security Section 1 — Introduction “If you look at these machines as just copiers or printers, you first wonder if you really need security.Then you realize conventional office equipment now incorporates significant technology advancesand capabilities that mak...
Page 5 - – imageRUNNER ADVANCE Controller Security; Device-Based Authentication; Department ID Mode; Active Directory environment on the network; Section 2 — Device Security
2.1 – imageRUNNER ADVANCE Controller Security The imageRUNNER ADVANCE series is built upon a new platform that provides powerfulenhancements to security and productivity. The new architecture centers on a new operating systempowered by an embedded version of Linux, which is quickly becoming the most...
Page 6 - Card-Based Authentication; uniFLOW Card Authentication
Canon imageRUNNER ADVANCE systems also ship with SSO-H, which supports directauthentication against an Active Directory domain using Kerberos or NTLMv2 as the authentication protocol. SSO-H does not require any additional software to perform the user authentication as it is able to directly communic...
Page 8 - Privileges by Access Level; Device Function
The following describes the various Base access levels (roles) that are available: The following functions and features can be restricted: 8 White Paper: Canon imageRUNNER ADVANCE Security Section 2 — Device Security Privileges by Access Level Predefined Role Access Privileges Administrator Given pr...
Page 9 - Function Level Authentication; Scan and Send Security; Address Book Password
When the Access Management System has been enabled, users must log in to the device using SSOuser authentication. Access Management System supports authentication through local deviceauthentication as well as Active Directory using SSO-H*, which includes support for KerberosAuthentication. Once a us...
Page 11 - Print Driver Security Features; Print Job Accounting; USB Block; – Third Party MEAP Application and Development
Print Driver Security Features Print Job Accounting A standard feature in Canon’s printer drivers, print job accounting requires users to enter anadministrator-defined password prior to printing, thereby restricting device access to thoseauthorized to print. Printing restrictions can be set using De...
Page 12 - – Document Security; Secure Printing; uniFLOW Secure Print; Section 3 – Information Security
Protecting your organization’s confidential information is a mission that Canon takes seriously. From your documents, faxes and e-mails to the underlying data on the internal hard disk drive and in memory, Canon has built in many controls to help ensure that your information does notbecome compromis...
Page 13 - Document Storage Space Protection; Mail Box Security
Document Storage Space Protection Mail Box Security Each imageRUNNER ADVANCE systemships standard with Mail Boxes for storageof scanned and printed data. Mail Boxsecurity is provided by the ability to designate a unique password for access.Once a document is stored in the Mail Box(if the Mail Box is...
Page 14 - Other Document Security Capabilities; Watermark / Secure Watermark
14 White Paper: Canon imageRUNNER ADVANCE Security Administrators can manage the Advanced Box feature through the Remote UI interface and perform the following actions: • Create user accounts and define type (Admin vs. End User)• Activate authentication and enable Personal Space• Register network de...
Page 15 - Digital Signature PDF (Device and User Signature); Rights; Document Scan Lock & Trace
15 White Paper: Canon imageRUNNER ADVANCE Security Digital Signature PDF (Device and User Signature) Within Scan and Send, users can add digital signatures that verify the source and authenticityof a PDF or XPS document. When recipients open a PDF or XPS file that has been saved with adigital signat...
Page 16 - Data at Rest; HDD and RAM Data Protection
16 White Paper: Canon imageRUNNER ADVANCE Security The Scan Lock feature enables the following restrictions to be applied to a document: • Complete Restriction: No one can make any copy/send/fax.• Password Authentication: Allows the ability to make copy/send/fax only if the proper password is entere...
Page 17 - HDD Data Encryption Kit
17 White Paper: Canon imageRUNNER ADVANCE Security information from environments, where sensitive information is processed, by analyzing the hard disks from these devices. In order to help protect your sensitive and confidentialinformation Canon imageRUNNER ADVANCE systems include a standard hard di...
Page 21 - Essentials Workflow Composer; Data in Transit; Encrypted Secured Print
Essentials Workflow Composer Canon imageRUNNER ADVANCE Essentials includes the Workflow Composer component toenable users and administrators to create custom workflows that automate redundant tasksand provide integration with back-end systems via connectors. Administrators are able to create workflo...
Page 22 - Super G3 Fax Board and Multi Line Fax Board; Super G3 Fax Board Communication Mechanism; Other Fax Features; Fax Forwarding / Mailbox Fax Forwarding
3.3 – Fax Security Super G3 Fax Board and Multi Line Fax Board Canon imageRUNNER ADVANCE systems that support Super G3 fax capabilities with the optionalSuper G3 Fax Board installed can be connected to the Public Switched Telephone Network for sendingand receiving of fax data. In order to maintain t...
Page 23 - Fax Storage Space; Fax Mail Box and Advanced Box Fax Security
Advanced Box Fax Forwarding & Fax Received Notification Similar to the Fax Forwarding function, imageRUNNER ADVANCE systems support the capabilityto define separate forwarding rules based on the line upon which the fax was received. Eachfax can be routed to a specific shared or personal space Ad...
Page 24 - – Network and Print Security (Canon Network Printer Kit Only); Enabling/Disabling Protocols/Applications; Section 4 – Network Security
4.1 – Network and Print Security (Canon Network Printer Kit Only) Canon imageRUNNER ADVANCE systems include a number of highly configurable network security features that assist insecuring information when the optional Network Print Kit is installed. Standard network security features include the ab...
Page 26 - Authentication and Encryption Method:; One of the following methods must be set for the device.; Key Exchange Protocol
See the imageRUNNER ADVANCE system manual for the specific device in question for additionalinstructions on registering IPSec-based security policies. Authentication and Encryption Method: One of the following methods must be set for the device. • AH (Authentication Header) A protocol for certifying...
Page 28 - There are three possible scenarios that are explored:; – Mail Server Security; SMTP Authentication
There are three possible scenarios that are explored: • • D Da atta a w wiitth h a a vviirru us s a atttta acch he ed d iin n tth he e e e--m ma aiill:: All file attachments except for ‘TIFF” files received in the e-mail are discarded immediately afterreception. • • V Viirru us se es s p prre ette e...
Page 29 - Section 5 – Security Monitoring & Management Tools
Canon provides a number of tools to help organizations enforce their internal company policies andmeet regulatory requirements. Whether a single imageRUNNER ADVANCE system is deployed, or afleet of them, these solutions provide the ability to audit usage and limit access to features and functions en...
Page 30 - Section 6 – Logging & Auditing
Few security procedures can completely prevent the intentional leak of confidential information whilemaintaining high productivity, but if an occurrence does happen it is important to be able to trace itto the source. Canon has developed a number of cutting-edge technologies to provide administrator...
Page 31 - – Canon imageWARE Accounting Manager; Canon imageWARE Accounting Manager provides the capability to:; – Canon imageRUNNER ADVANCE Tracker
6.2 – Canon imageWARE Accounting Manager Canon imageWARE Accounting Manager provides enhanced audit tracking capabilities to the end-userenvironment. In addition to tracking usage by Department ID or SSO account, imageWARE AccountingManager in conjunction with SSO will provide the ability to track u...
Page 32 - Section 7 – Canon Solutions & Regulatory Requirements
Canon is dedicated to providing the most secure multifunctional printers available on the markettoday. Many of our products meet or exceed the requirements of government agencies and privateentities as they relate to security certifications and industry regulations. 7.1 – Common Criteria Beginning o...
Page 34 - Section 8 – Conclusion
Since initially introduced, the highly successful Canon imageRUNNER series of devices have rapidlygrown in both the breadth and depth of features and functions. With each release, these devices havebecome increasingly integrated within the IT and network infrastructure. As with any networkeddevice, ...
Page 35 - – Canon Security Recommendations Quick Reference; of data stored on internal Hard Disk Drives; Section 9 – Addendum
9.1 – Canon Security Recommendations Quick Reference Each customer’s needs are different, and while the security of corporate data is ultimately the responsibility of the customer, the security technologies outlined below may help support your organization's information security needs. The following...
Page 36 - – Canon imageRUNNER ADVANCE HDD Security; Fu
36 White Paper: Canon imageRUNNER ADVANCE Security 9.2 – Canon imageRUNNER ADVANCE HDD Security Section 9 – Addendum Common Criteria Certification EAL3 N/A Supported Devices iR ADV C5051, C5045, C5035, C5030,C7065, C7055, C9075 PRO, C9065 PRO iR ADV C5051, C5045, C5035, C5030,C7065, C7055, C9075 PRO...
Page 37 - Regulatory Disclaimer:
The information provided in this document is the most current information available at the time of its creation. Canonhereby expressly disclaims all warranties of any kind, express or implied, statutory or non-statutory, in relation to theinformation provided in this document. In no event shall Cano...