openPR Logo
Press release

Two IEEE Protection Profiles for Multi-Function Printers Evaluated by atsec information security

09-22-2010 11:36 AM CET | IT, New Media & Software

Press release from: atsec information security

Two IEEE Protection Profiles for Multi-Function Printers

Austin, TX/Munich, Germany – Two Protection Profiles (PPs) defining agreed security functional and security assurance requirements for multi-function printers in different environments have been evaluated by atsec on behalf of the IEEE.

Each PP postulates different assumptions of the attack potentials and threat scenarios. These PPs each include unique base functionality and contain further SFR packages that specify additional requirements in case the printer implements mechanisms covered by the packages. For example, a supplementary package of SFRs for non-volatile storage is defined - if the device under evaluation includes non-volatile storage, then the ST must include the package for non-volatile storage.

PP 2600.1 was evaluated under the NIAP’s CCEVS scheme and is listed as a US Government approved profile on the NIAP website. The IEEE Standard for a Protection Profile in Operational Environment A is aimed at “hardcopy devices in a restrictive commercial information processing environment in which a relatively high level of document security, operational accountability, and information assurance are required. Typical information processed in this environment is trade secret, mission critical, or subject to legal and regulatory considerations such as for privacy or governance. This environment is not intended to support life-critical or national security applications”.

PP 2600.2 was evaluated under the BSI scheme and is available from the BSI website. The IEEE Standard for a Protection Profile in Operational Environment B is aimed at “hardcopy devices in a commercial information processing environment in which a moderate level of document security, network security, and security assurance are required. Typically, the day-to-day proprietary and nonproprietary information needed to operate an enterprise will be handled by this environment”.

Helmut Kurth, atsec’s Chief Scientific Officer, co-editor of ISO/IEC TR 15446 “A guide for the production of Protection Profiles and Security Targets” who advised IEEE in the development of the Protection Profiles: “The IEEE developed family of Protection Profiles represent another example of an industry consortium harmonizing the security functionality for a specific class of products (in this case multi-function printer devices) and specifying those functions in the form of a Common Criteria protection profile. It was also the first time the package concept defined in the Common Criteria has been used extensively to cover the different types of function that can be offered. The smart card industry has shown that protection profiles developed by industry consortiums get a much wider acceptance than those just developed by governments and it also shows that industry sees the benefit of harmonizing the requirements for security functionality and assurance measures using the Common Criteria as a basis.”

The PPs which are available as IEEE standards free of charge from the IEEE at http://standards.ieee.org/getieee/2600.

The IEEE coordinated development of the PPs with a group of industry sponsors from the multi-function device industry including Canon, Fuji Xerox, Hewlett-Packard, InfoPrint Solutions, Konica Minolta, Kyocera Mita, Lexmark, Océ, Oki Printing Solutions, Ricoh, Samsung, Sharp, Toshiba TEC Corporation, and Xerox. PPs developed by such industry collaborations provide a useful and meaningful standard for industry accepted security functionality and assurance levels.

Companion standards, IEEE 2600.3™-2009 Standard Protection Profile for Hardcopy Devices in IEEE Std 2600™-2008 Operational Environment C* and IEEE 2600.4™-2010 Standard Protection Profile for Hardcopy Devices in IEEE Std 2600™-2008 Operational Environment D* are available from the IEEE Shop

With Common Criteria evaluation laboratories accredited under three national schemes (U.S. National Information Assurance Partnership's (NIAP), Common Criteria Evaluation and Validation Scheme (CCEVS), German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik (BSI) and Swedish CC scheme Sveriges Certifieringsorgan för IT-säkerhet (CSEC) operated by FMV) atsec was well positioned to evaluate the PPs for both NIAP and BSI.

About atsec information security
atsec information security (www.atsec.com) is an independent, standards-based information technology security services company that combines a business-oriented approach to information security with in-depth technical knowledge and global experience. atsec was founded in Munich, Germany in 2000 and has extensive international operations with offices in the U.S., Germany, Sweden, and China. atsec's service include formal laboratory testing and evaluation, independent testing and evaluation as well as information security consultancy.
atsec also offers evaluation and testing services leading to formal certification for IT security including evaluation under Common Criteria schemes in the U.S., Germany, and Sweden; This is supported by cryptographic module and algorithm testing under the Cryptographic Module Validation Program of the National Institute of Standards and Technology (NIST) in the U.S. and Communications Security Establishment Canada (CSEC) in Canada.
atsec works with such leading global companies as Apple, Cray, Hewlett-Packard, IBM, Microsoft, Oracle and Red Hat.

Media Contact:
Andreas Fabis, fabis@atsec.com
Marketing Director
atsec information security
(512) 615-7317

atsec USA

atsec information security corporation
9130 Jollyville Road, Suite 260
Austin, TX 78759
USA
T +1-512-615-7300
F +1-512-615-7301

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release Two IEEE Protection Profiles for Multi-Function Printers Evaluated by atsec information security here

News-ID: 145340 • Views:

More Releases from atsec information security

atsec information security is now operating a Certification Body accredited according to ISO/IEC 17065
atsec information security is now operating a Certification Body accredited acco …
AUSTIN, TX - atsec is pleased to announce that atsec information security AB has been accredited as a certification body by SWEDAC, the national accreditation body in Sweden, to provide Common Criteria (CC) certifications of IT products. With over 20 years of experience as a CC evaluation lab, atsec has taken the step to become a CC certification body. We have an experienced and knowledgeable team, that has helped many national schemes
Call for Papers for the Second International Cryptographic Module Conference
Mark Your Calendar: ICMC 2014, November 19-21, Hilton Washington D.C., Rockville, MD ICMC brings together experts from around the world to confer on the topic of cryptographic modules, with emphasis on their secure design, implementation, assurance, and use, referencing both new and established standards such as FIPS 140-2 and ISO/IEC 19790. We are focused on attracting participants from the engineering and research community, test laboratories, government organizations, the procurers, deployers and administrators
atsec information security Opens South East Asia Office
atsec information security Opens South East Asia Office
Bangkok, Thailand – atsec information security is pleased to announce the opening of its atsec South East Asia (atsec SEA) office in Bangkok, Thailand. Since the year 2000, the atsec group of companies have been established experts in information security including Common Criteria, FIPS 140-2, PCI, ISO 27001, and hardware testing. As part of the atsec group of companies, atsec SEA’s objective is to promote information security and information assurance in
atsec completes FIPS 140-2 testing of Watchdata's WatchKey USB Token at Security Level 2
atsec completes FIPS 140-2 testing of Watchdata's WatchKey USB Token at Security …
Austin, TX - atsec information security is pleased to announce that its customer, Watchdata Technologies Pte Ltd. (branded as “Watchdata”), received a FIPS 140-2 validation certificate #1640 for the WatchKey USB Token under the CMVP (Cryptographic Module Validation Program) by the National Institute of Standards and Technology (NIST), USA and the Communication Security Establishment of Canada (CSEC). The successful validation result is published on the CMVP’s official website at: http://csrc.nist.gov/groups/STM/cmvp/validation.html The issued

All 5 Releases


More Releases for IEEE

Perle Closes KRACK IEEE 802.11 Security Standard Vulnerability
NASHVILLE, November 22nd, 2017 — Perle Systems, a global manufacturer of secure device networking hardware, has released new firmware for the IOLAN SDS W Secure Wireless Device Server to patch the recently disclosed vulnerability found in WPA2. Serious weaknesses were recently discovered in the WPA2 protocol standard, which secures all modern protected WiFi networks. Using Key Reinstallation attaCKs (KRACK), it is possible for an attacker to harvest sensitive information being transmitted
Optical Gigabit Ethernet Becomes IEEE Standard
KDPOF Welcomes New IEEE 802.3bv(TM) Specification for Robust and Reliable Optical Data Transmission in Automotive Applications KDPOF – leading supplier for automotive gigabit connectivity over POF (Plastic Optical Fiber) – welcomes IEEE's publication of the new standard amendment for 1000 Mb/s Ethernet operation over plastic optical fiber. As an amendment to the IEEE 802.3™ standard, IEEE Std 802.3bv(TM) for gigabit Ethernet over POF defines physical layer specifications and management parameters for
IEEE 1588 protocol software with new features for the telecommunication sector
The IEEE 1588 protocol software from IXXAT enables networking devices with accurate and reliable time synchronization for automation, automotive, measurement and telecommunication applications. Depending on the microcontroller system and the type of network employed, IXXAT’s IEEE 1588-2008 PTP software is able to attain time synchronization accuracy in the nanosecond range. The new version 1.05 now supports the basic requirements of the ITU-T G.8265.1 telecom specification for "Packet Timing Signal Fail Mechanism",
GÖPEL electronic demonstrates IJTAG (IEEE P1687) support in SYSTEM CASCON
At International Test Conference (ITC) 2011 in Anaheim, CA, GÖPEL electronic demonstrates a prototype version of the company’s JTAG / boundary-scan software platform SYSTEM CASCON™ with integrated tools supporting the current version of the upcoming IEEE P1687 (IJTAG) standard. IEEE P1687 focuses on the standardization of the access to and the documentation of the control of chip-embedded instruments, without limiting the number or type of instruments. Compatible test systems allow
IEEE Introduces Advanced Metering Standards for the first time in India
Chennai, September 12, 2011: IEEE Standards Association (IEEE-SA), a globally recognized standards setting body within IEEE, today officially introduced two new standards IEEE 1701TM and IEEE 1702TM, to create a multi source plug and play communications environment for implementation of diverse smart metering devices, for the first time in India. While deployment of smart Meters and Advanced Metering Infrastructure (AMI) has been recognized as an important steps towards Smart
LayerZero Co-Founder Jim Galm Elevated To Senior IEEE Member Grade
Jim Galm, Vice President and Chief Technical Officer of LayerZero Power Systems, Inc., has been selected as a Senior Institute of Electrical and Electronics Engineers (IEEE) member. The grade of Senior Member requires experience reflecting professional maturity and significant professional achievements. Jim Galm has contributed towards significant discoveries and advancements in the power distribution industry, having authored numerous patents, including LayerZero’s Dynamic Phase Compensation Technology. Jim Galm