Seals for the Department of the Navy and DON CIO Department of the Navy - Chief Information Officer Web Site - The DON IT Resource
MAY
18
Seals for the Department of the Navy and DON CIO Home | Policy and Guidance | Products | Ask an Expert | Events | Other Govt Sites | Contact Us
RSS Feeds
 
Text Size: Text Size NormalText Size Large Print This Page Print Page    Email This Article E-mail
Copier/Printer May Present Information Security Risks
By DON CIO Privacy Team
Published, October 6, 2009
Privacy Tip
Two recent personally identifiable information (PII) breach incidents involving the turn in of reproductive office equipment highlight the fact that many people do not know that copiers and printers present information security challenges.
Many copiers, printers and multi-function reproductive machines manufactured today have hard drives capable of storing documents that have been scanned, printed or faxed as digitized documents. These machines are often connected to Department of the Navy networks to ease workload and increase efficiency. The purpose of this Privacy Tip is to increase awareness regarding the breach potential of PII and other sensitive information and some best practice safeguards that users should consider to better safeguard information. This information will be superseded by a new DON policy currently in draft and under review.

Reproductive office equipment manufactured during the past seven years uses hard drives that store digital images. While much of the hard drive space is used for processing, once the hard drive memory has been exceeded, files are automatically overwritten. "Cap points" limit the number of pages stored to hard drives, and the cap limitation can vary on each make and model number. Small print jobs may only be stored in random access memory (RAM), depending on the type of machine, and the files are overwritten with each new print request or are lost when the machine is powered off. The newest reproductive office equipment may advertise that their hard drives use encryption software to safeguard the data, but as of this writing, that encryption capability is not DON approved. Approved DON encryption solutions, such as Guardian Edge, do not encrypt reproductive equipment hard drives. Ownership of the copier/printer equipment may also present challenges when equipment is repaired or when turned in for replacement. DON copiers/printers and multi-function machines are either leased from a vendor or are Government owned.

Networked reproductive office equipment has also been in use for the past several years and is subject to some of the same vulnerabilities that affect IT systems on the network, including attacks by hackers and susceptibility to the use of malicious software and viruses.

Stand-alone facsimile or FAX machine memory is generally non-volatile and is lost as soon as the machine is turned off.

Tighter policy controls regarding the turn in of this equipment are currently in draft. Prior to the release of new policy guidance by the DON CIO, the following should be considered as a best practice.

For CLASSIFIED copiers/printers: Guidance for reproductive equipment can be found in SECNAV M-5510.36, para 7-15(2), (3).

For UNCLAS copiers/printers:
  • Identify the hard drive capabilities of your photographic equipment and educate office personnel with that information.
  • For Government-owned equipment, hard drives should be removed and physically destroyed prior to disposal. Hard drives are not easily accessible, so removal will probably require a technician to accomplish. Future DON guidance will require that all hard drives be physically destroyed when equipment is turned in prior to disposal.
  • For leased equipment, the hard drives should be reformatted to remove all data on printer/copier hard drives. Refer to the manual or service technician for the reformatting process. Future DON guidance may address new vendor contract language that requires removal and physical destruction of the hard drive before the equipment leaves Government control.
  • Place a sticker or placard on the copier/printer with a banner: "Warning, this Government-owned copier uses a hard drive that must be physically destroyed prior to turn-in" or "Warning, this leased copier uses a hard drive that must be reformatted prior to turn-in."
Tagged With: Tagged with: Cybersecurity, IDManagement, Privacy
Related Events
DON IT Conference, East Coast 2012
DON IT Conference, West Coast 2012
Related Industry News
Computer Data on 103,000 Va. Adult Ed Students Misplaced
5 Technologies on The Way Out in 2012
6 Security Trends to Watch in 2010
Analysis: Push to Open Government Elevates Risk of Data Leaks
And the Password is... Obvious
Apple's iPad Security Breach Reveals Vulnerability of Mobile Devices
Avoiding Facebook Regrets: Keep Your Friends Close
Better Security Boosts Agencies' Use of Wireless Devices
Bills Target International Cyber Criminals
Civil Liberties Groups Fight Biometric IDs
Coalition Calls for Update of Privacy Act
Company Says 3.3M Student Loan Records Stolen
Congressmen Poke Facebook Over Privacy Breaches
Controversial Cyber Bill Sails Through House
Could Do-Not-Track Option Become a Reality?
Crypto Rules Changing for ID Cards
Cryptographic Showdown, Round 2: NIST Picks 14 Hash Algorithms
DARPA Seeks to Build Attack-Resistant Secure Cloud
DHS Extends States' Real ID Compliance Deadline
DHS to Sweep up More Data on Employees, Contractors
DHS to Track Video-Game Consoles
DISA Issues Identity Management RFI
Do We Need a U.N. Cyber Security Council?
Does RFID Present Privacy Risks?
E-Verify Could Add Biometrics
Facebook Changes App Permissions, But Critics Say It's Not Enough
Facebook IDs Hacker Who Tried to Sell 1.5M Accounts
Facebook Outlines Privacy Changes
Facial Recognition Technology Creates Privacy Headaches for Agencies
FBI Finds Technology for Information Security
FBI Proposing 'Wiretapping' Law for Social Media, Web Email, According to Report
Federal Reserve Hacker Indicted
Finally, an Alternative to the Tyranny of Passwords?
Former Barclays Programmer Gets Four Years for Role in TJX Attacks
French Arrest Cyber-Crime Suspect for U.S.
FTC Takes On Online Privacy
FTC: Companies Unknowingly Exposing Data to Fraud
Google CEO Exposes Dark Side of Social Networking
Google Releases Data on Governments' Demands for User Data, Site Censorship
Google Uses Personal Data to Tailor Up to 20% of Searches
Got a Weak Password? Beware of Mr. Morto.
GSA Employee's Error Exposes Staff to Potential Identity Theft
GSA Tool Lets People Verify Genuine Federal Social Media Accounts
Hacker Breaches Security at Pentagon Federal Credit Union
Hacker Demands $10M Ransom for Data
Hackers Steal Electronic Data From Top Climate Research Center
Heartland Breach Shows Why Compliance is not Enough
Heartland Hacker Sentenced to 20 Years
Heartland Hacker to be Sentenced
HHS Publishes Online List of Patient Data Breaches
HHS Releases Guidance on Securing Electronic Health Data
House Backs Biometrics in DHS 2010 Spending Bill
How to Secure Data in Cloud? Stick With it Like Glue
How to Stop Facebook Friends From Tracking You
ID Management's Weakness: Few Want To Use It
'Identity Ecosystem' To Replace Passwords, Draft Strategy Suggests
In New Cyber Battle, Info is the Goal, 'Stupid' is an Enemy
Industry CTOs Want Government to Lead on Identity, Standards
Information-Sharing Platform Hacked
Internet Disruptions Raise Tensions for Google in China
Is a Secure Password All in The Typing?
IT Central to Debate Over Real ID, PASS ID
Kundra's Parting Gift? 10 Lessons in IT Management
Laptop With Personal Data About Thousands Stolen from Army Employee
LulzSec Reborn? Military Dating Data Dump May be Work of Reformed Group
Microsoft Launches Tech Policy Web Site
Microsoft to Congress: Time to Seed Cloud Computing
Mismailing Causes VA Information Breach
Missing Drive Had no Original Clinton Records, says National Archives
Momentum Builds for Federal Rules on Internet Privacy
NARA Suffers Data Breach
National Guard Bureau Tells What not to Write on Facebook
Network Solutions, GoDaddy Cease Registering Web Sites in China
New Cyber Threats Put Government in The Cross Hairs
New NIST Guidance Tackles Public Cloud Security
New Organization to Address Interoperability Between Social Media, ID Management
New Phishing Scam Targets Military Users, DFAS Warns
New Vishing Spree Strikes U.S.
NIST Proposes Privacy Controls for Federal Information Systems
NIST Takes on Risk Management and PIV Card Security
OMB Ends Federal Agency Decade-Long Cookie Ban
OMB Tells Agencies How To Treat Their Online 'Friends'
One Appeal Fails, Another Pending Today for E-Verify
One More Reason why Passwords are no Darn Good
Ongoing Storm of Cyberattacks is Preventable, Experts Say
Open Government Could Lead to Data Leaks
Open Government Initiative May Increase Security Woes
Panel OKs Bill That Would Increase Cybersecurity Oversight
Pay Up: The Most Common Type of Online Crime
Pentagon Computer Network Defense Command Delayed by Congressional Concerns
Personal Data of Reservists, Veterans at Risk in Recent Thefts
Printer Security: The Invisible Problem in Plain Sight
Privacy Battles Move to The Fore, But Who Are The Good Guys?
Proposed Laws on ID Tech Take Privacy to the Extreme
Protect Online Privacy Without Reading the Fine Print
Report: Obama Close to Appointing White House Cybersecurity Chief
Security Experts Scramble to Decipher Twitter Attack
Security Risks Evolve Alongside Social Media
Sensitive Information Protection Remains Tough
Software Configuration Controls Essential to Cybersecurity
Sony Says PlayStation Users' Data Protected, But Take Precautions Anyway
Survey: 9% Have Experienced ID Theft
The Biggest Threats to Security are Sitting Next to You
Trusted Identities Plan a 'Major Step' Toward Securing Online Transactions
Twitter Breach Revives Cloud Security Fears
U.S. Advisory Panel Calls for New Privacy Rules
U.S. Wants to Store European Travelers' Personal Data For 15 Years
VA Breach Blasted by Congressman
VA Seeks Info on Cloud-Based Health Care Collaboration
White House Plans Strategy for Better Cyber Authentication
WikiLeaks Could be Thwarted by New State Department System
Wikipedia, Others Staging Anti-SOPA Blackout; White House Weighs in
Will Feds Trust Nonfederal ID Card?
Wisen up to Handheld Security
Workshop to Explore Social-Media Privacy
Related News
Action Steps for Identity Theft Victims
Compliance Spot Checks Key to Successful Privacy Program
Defending Cell Phones and PDAs Against Attack
DoD Memo on PIV-I Credentials Released
DON Current and Future PKI and PKE Activities
DON Digital Signature and Encryption Policy for Emails Containing PII
DON Electronic Signature Policy Released
DON Enterprise Data At Rest Solution For All Non-NMCI Assets Is Awarded
DON IT Conference Presentations Available
DON SSN Reduction Plan
DON to Migrate to Use of Stronger Cryptographic Algorithms
Don't Get Caught by Phishing
Elements of a Good Privacy Program
Elements of a Good Privacy Program (Part Two)
GSA Awards BPA for Credit Monitoring Services
Guidance Updated for DAR Compliance Effort on Non-NMCI Networks
Handbook Provides Cyber Crime Prevention Tips
Identity Management Operations to Improve Cybersecurity
Improper Disposal of HR Documents
Insider Threat
PII and Records Management
PII Breach Articles from CHIPS Magazine
PII Has No Shelf Life
Privacy Must be Considered When Using Web 2.0 Tools
Privacy Policy on DON Publicly Accessible Websites
Privacy Tips
Protect Your Personal Information: It's Valuable
Protecting PII on Removable Storage Devices
Reduce PII in Electronic and Paper Files
Reduce PII Loss by Proper Disposal/Sanitization of Unclass Equipment
Reducing the Use of SSNs is Key to Securing PII
Rein in and Rethink the Use of Recall Rosters
Rules for Handling PII by DON Contractor Support Personnel
Safeguarding PII on the Command Shared Drive
Secure Those Laptops
SSNs to be Removed from Government ID Cards
Steps For Military Personnel to Take to Defend Against ID Theft
Supervisor Sends PII Without Encrypting Email
Tax Time Privacy Tips
Theft of Storage Media Containing PII
To Err is Human: Human Error is Main Cause of PII Breaches
Top 10 PII Lessons Learned
Un-Encrypted Email With NSPS Information
Unique DoD ID Replaces SSN
Use Caution With Wi-Fi
Web 2.0: Federal CIO Council Releases Guidelines for Secure Use of Social Media
Web Site Postings of PII
What You Should Know About Identity Theft
Why Peer-to-Peer File Sharing Is Not a Good Idea
Your Office Copier/Printer May Present Information Security Risks
Related Policy
Approval of External Public Key Infrastructures
Commander Access to Health Information
Common Access Card Eligibility for Foreign National Personnel
DoD Acceptance and Use of Personal Identity Verification-Interoperable (PIV-I) Credentials
DoD and DON Privacy Impact Assessment Guidance
DoD Compliance with Electronic Biometric Transmission Specification
DoD Health Information Privacy Regulation
DoD Implementation Guide for Transitional PIV II SP 800-73 v1
DoD Privacy Impact Assessment Guidance
DoD Social Security Number Reduction Plan
DoD-Wide Digital Signature Interoperability
DON Electronic Signature Policy
DON Encryption of Sensitive Unclassified Data at Rest Guidance
DON Enterprise Data At Rest Solution For All Non-NMCI Assets
DON IM/IT/Cyberspace Campaign Plan for Fiscal Years 2011-2013
DON Information Assurance Manual
DON Personally Identifiable Information Annual Training Policy
DON Personally Identifiable Information Training Requirement
DON Policy Updates for Personal Electronic Devices Security and Application of Email Signature and Encryption
DON Policy Updates for Use of NIPRNET Public Key Infrastructure Software Certificates
DON Privacy Impact Assessment Format Guidance
DON Privacy Impact Assessment Guidance
DON Privacy Program
DON Public Key Infrastructure Implementation Guidance
DON Secure Hash Algorithm Migration
DON Social Security Number Reduction Plan for Forms Phase One
Encryption of Sensitive Unclassified Data at Rest on Mobile Computing Devices and Removable Storage Media
Federal Information Processing Standard 201-1: Personal Identity Verification of Federal Employees and Contractors
Instructions on Complying with President's Memorandum of May 14, 1998: "Privacy and Personal Information in Federal Records"
Loss of Personally Identifiable Information Reporting Process
National Industrial Security Program Operating Manual
Policy for a Common Identification Standard for Federal Employees and Contractors
Policy for Digital Signature Functionality and Acceptance
Privacy Act of 1974
Privacy Act Program Update
Processing of Magnetic Hard Drive Storage Media for Disposal
Protecting Personally Identifiable Information on DON Shared Drives and Application Based Portals
Protection of Sensitive Department of Defense Data at Rest on Portable Computing Devices
Recall Rosters
Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency IT Investments
Safeguarding Personally Identifiable Information
Safeguarding Personally Identifiable Information
Safeguarding Personally Identifiable Information
Safeguarding Personally Identifiable Information (PII)
Safeguarding Personally Identifiable Information from Unauthorized Disclosure
Social Security Numbers Exposed on Public Facing and Open Government Websites
Updated Plan to Remove Social Security Numbers from DoD Identification Cards
Web 2.0: Utilizing New Web Tools
Withholding of Information that Personally Identifies DoD Personnel
Related Products
DON Cyber Crime Handbook
Labels for Electronic Devices Containing Hard Drives
Personally Identifiable Information Posters
Related Reference
2009 DON CIO IM/IT PIA Workshop Brief
2009 DON CIO IM/IT PII Brief
Approved Use Cases for Systems Collecting SSNs
BUPERS Safeguarding PII Presentation
Department of the Navy Personally Identifiable Information Sample Compliance Spot Checklist
Disclosure Accounting Form (OPNAV 5211/9 (MAR 1992))
DoD Privacy Impact Assessment Template
DoD Privacy Program Resources
DON SSN Reduction Review Form SECNAV 5213/1 (Jul 2010)
DON Users Guide to Personally Identifiable Information
Fair Information Practices
General Purpose Privacy Act Statement (OPNAV FORM 5211/12)
Guidelines for Establishing a New Privacy Act System of Records Notice
How and When to Write a Privacy Act Statement
How to Find Your DoD ID Number
How to Make a Privacy Act Request
How to Obtain Copies of Military Personnel Records
Identifying Privacy Act Systems of Records You May Be Using
Instructions for Using WinZip to Encrypt Files
Inventory of DON Systems With Completed Privacy Impact Assessments
May 2009 IM/IT Conference Identity Theft Brief
Methods for Hard Drive/Disk Destruction
OMB Information Collection Number
Overview of the Privacy Act of 1974 (2010 Edition)
PEO EIS Portal Procedures for Safeguarding PII
PII Breach Reporting Forms
PII Breach Reporting Resources
Potential Consequences for Failing to Safeguard PII
Privacy Act Desk Reference Guide
Privacy Act Exemptions
Privacy Act Resources
Privacy Act System of Records Notices
Privacy Briefs
Privacy Frequently Asked Questions
Privacy Impact Assessment Resources
Privacy Impact Assessment Signature Routing Guidance
Privacy Impact Assessment Template "Gouge"
Privacy Impact Assessment Template Risk Mitigation Question Responses
Privacy Information and Resources
Privacy Recommended Reading List
Privacy Resources for Military Members and Their Families
Privacy Training and Compliance Resources
Privacy-Related OMB Memoranda
Publically Accessible Website Privacy Resources (including Official DON Social Networking Sites)
Recommended Facebook Privacy Settings
Reporting PII Breach Notifications
Safeguarding PII
Sample Checklist for Conducting Privacy Act Assessment/Staff Visits
SSN Reduction Frequently Asked Questions
SSN Reduction Plan Resources
Take the DON Privacy Quiz!
Unique Investment Identifiers for FY2013