University of Hawaiʻi System

Multi-Function Devices (MFD) & Internet of Things (IoT) Devices — Minimum Security Standards

Last Updated 2023-02-06

Modern printers, copiers, scanners and fax machines generally utilize digital storage and communications capabilities that can present security vulnerabilities when not properly configured and actively managed. These devices are commonly referred to as Multi-Function Devices (MFD).

Internet-of-Things (IoT) devices are any object or device that sends and receives data automatically through the internet. This can include tags, sensors, and devices that interact with people and share information from machine to machine.

Please refer to the Implementation Guides for assistance with implementing the minimum security standard for your device.

Key


Item Description
Implementation required
Implementation recommended
Recurring task

When working with Regulated Data, please refer to the applicable Standard, Act, or Policy (e.g., CMMC, PCI DSS, HIPAA, FERPA, NIST SP800-171, etc.) for specific details on any additional controls needed.

The standards listed below are adapted from a subset of the Center for Internet Security's (CIS) Controls, which are a prioritized set of actions that collectively form a defense-in-depth set of best practices that mitigate the most common attacks against systems and networks. The subset of CIS Controls were chosen based on their applicability to the University of Hawaiʻi.


If a standard cannot be implemented in your environment for any reason, please contact infosec@hawaii.edu for consulting.


Quick Reference

#

Standards

Institutional Data Category

Patching Recurring Task

Public

Restricted

Sensitive

Regulated

Enable automatic firmware and software updates if possible.
Install standard firmware and software security patches on a monthly basis for MFDs and IoT devices.
Firewall Configuration Recurring Task

Public

Restricted

Sensitive

Regulated

Configure and manage a network-based firewall with a default deny all policy. Only the minimum number of services should be allowed through the firewall.
Password Security Recurring Task

Public

Restricted

Sensitive

Regulated

Ensure that all university owned MFDs & IoT devices have strong and unique password protected individual logins for all local and remote accounts.
Ensure that all administrative web application interfaces used to manage MFDs or IoT devices have strong and unique password protected logins for administrative accounts.
Data Management Recurring Task

Public

Restricted

Sensitive

Regulated

Utilize the University's records management process for .
Securely dispose of Institutional Data following our Disposal Guidelines.
Encryption Recurring Task

Public

Restricted

Sensitive

Regulated

Ensure that data is encrypted with a secure encryption algorithm while in transit.
Ensure that files containing Sensitive and Regulated data are encrypted or stored in an encrypted file container such as Veracrypt.
Asset Management Recurring Task

Public

Restricted

Sensitive

Regulated

Maintain an updated inventory of all software and hardware assets.
Ensure that hardware and software assets are fully supported by their vendors.
Review asset lists on a monthly basis. Remove or replace unauthorized and end-of-life assets if possible.
Data Inventory Recurring Task

Public

Restricted

Sensitive

Regulated

Complete the annual Personal Information Survey (PIS).
Secure Access Recurring Task

Public

Restricted

Sensitive

Regulated

Access applications and manage software over a secure encrypted connection (SSH, HTTPS, etc.).
Limit access to devices by authorized IPs if possible.
Secure Configuration Recurring Task

Public

Restricted

Sensitive

Regulated

Ensure that MFDs and IoT devices are configured following industry security best practices. Refer to the MSS Implementation Guides for specific configuration recommendations
Uninstall or disable unnecessary and unused services.
Event Logging Recurring Task

Public

Restricted

Sensitive

Regulated

Enable logging of system, security, and application events.
Retain logs for at least 90 days. Adequate log storage must be accounted for.
Review audit logs on a weekly basis.
Network Security Recurring Task

Public

Restricted

Sensitive

Regulated

Utilize network segmentation to address least privilege by isolating MFDs & IoT devices from critical services.
Maintain network architecture diagrams.
Utilize Wi-Fi Protected Access 2 (WPA2) with AES-128 or greater and a strong password for wireless networks.
Access Control Recurring Task

Public

Restricted

Sensitive

Regulated

Maintain an updated access control list of user roles, accounts and permissions for local/remote file systems, databases, and applications.
Grant access and apply access privileges to systems and services on a need to know basis.
Revoke privileges to systems and services upon employee termination, rights revocation, or role change.
Account Management Recurring Task

Public

Restricted

Sensitive

Regulated

Restrict administrator privileges to individually dedicated administrator accounts.
Remove dormant accounts (45 days of inactivity).
Disable default system and software accounts or make them unusable.
Review account privileges and permissions quarterly.
Vulnerability Scanning Recurring Task

Public

Restricted

Sensitive

Regulated

ÌÇÐÄVlog¹Ù·½ Vulnerability Scan Site
Perform vulnerability scans using ScanÌÇÐÄVlog¹Ù·½ on a monthly basis.
Remediate all High and Critical severity vulnerabilities within 7 days.