S 2.397 Planning the use of printers, copiers, and all-in-one devices

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Head of IT, Administrator

A basic requirement for the secure use of printers, copiers, and all-in-one devices is appropriate planning in advance. The use of printers can be planned in several steps according to the top-down design principle: based on a basic concept for the overall system, concrete plans are specified for subcomponents in detailed subconcepts. Not only do the aspects classically associated with the term "security" need to be planned, but also normal operating aspects that can lead to requirements in the area of security.

In the basic concept, focus should be placed on handling the following aspects, for example:

The following aspects of a concept should be considered when planning the use of printers, copiers, and similar devices:

General aspects:

Rules for document access: Safeguards must be implemented that make it more difficult to access other usersÂ’ documents:

Protection of network printers: Access to the network printers should be restricted (see S 4.301 Restrictions on access to printers, copiers, and all-in-one devices):

Availability: Precautions must be taken in case of the failure of the print servers or individual devices. Appropriate maintenance contracts, for example, can reduce the downtime resulting from technical defects (see S 6.105 Contingency planning for printers, copiers, and all-in-one devices).

Encryption: In safeguard S 4.300 Information security for printers, copiers, and all-in-one devices, the following questions, which play an important role in planning, are examined, among others:

All decisions made in the planning phase must be documented so that they can be understood at a later point in time. When documenting, make sure the information is appropriately organized and easy to understand.

Review questions: