{"product_id":10373,"v_id":10373,"product_name":"Lexmark X466, X656, X658, X738, X860, X862, and X864 Multi-Function Printers and InfoPrint 1940, 1870, 1880, Color 1866, 1948, 1968, 1988 Multi-Function Printers","certification_status":"Not Certified","certification_date":"2011-02-02T00:02:00Z","tech_type":"Multi Function Device","vendor_id":{"name":"Lexmark International, Inc.","website":"http://www.lexmark.com"},"vendor_poc":"Sean Gibbons","vendor_phone":"859-232-2000","vendor_email":"gibbonss@lexmark.com","assigned_lab":{"cctl_name":"COACT, Inc. Labs"},"product_description":"<p><strong>The TOE provides the following functions related to Multi Function Printers (MFPs):</strong></p>\r\n<ol type=\"A\">\r\n<li>Printing &ndash; producing a hardcopy document from its electronic form</li>\r\n<li>Scanning &ndash; producing an electronic document from its hardcopy form</li>\r\n<li>Copying &ndash; duplicating a hardcopy document</li>\r\n<li>Faxing &ndash; scanning documents in hardcopy form and transmitting them in electronic form over telephone lines, and receiving documents in electronic form over telephone lines and printing them in hardcopy form</li>\r\n</ol>\r\n<p>All of the MFPs included in this evaluation provide the same security functionality.  Their differences are in the speed and type (color or monochrome) of printing.  For the InfoPrint MFPs, a common brand name is used for MFPs both with and without a hard drive.  Therefore, the MT-Model is also included in the specification to limit the MFPs in this evaluation to only those including a hard drive.&nbsp; Multiple MT-Models are listed since they distinguish options such as staplers and paper tray sizes.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the Lexmark X466 (LR.BR.P311CCa), X656 (LR.MN.P311CCa), X658 (LR.MN.P311CCa), X738 (LR.FL.P311CCa), X860 (LR.SP.P311CCa), X862 (LR.SP.P311CCa) and X864 (LR.SP.P311CCa) Multi-Function Printers and InfoPrint 1940 MT-Model 4570-gh1, gh2, gt1, gt2 (LR.BR.P311CCa), 1870 MT-Model 4567-gh1, gh2, gt1, gt2 (LR.MN.P311CCa), 1880 MT-Model 4568-gs1, gs2, gf1, gf2, gb1, gb2, g11, g12, g21, g22, g31, g32 (LR.MN.P311CCa), Color 1866 MT-Model 4915-gd1, gd2, gt1, gt2 (LR.FL.P311CCa), 1948 MT-Model 4857-g01, g02, g11, g12 (LR.SP.P311CCa), 1968 MT-Model 4858-gt1, gt2, g21, g22 (LR.SP.P311CCa) and 1988 MT-Model 4859-gt1, gt2, g31, g32 (LR.SP.P311CCa) Multi-Function Printers meets the security requirements contained in the Security Target.</p>\r\n<p>The criteria against which the Lexmark X466 (LR.BR.P311CCa), X656 (LR.MN.P311CCa), X658 (LR.MN.P311CCa), X738 (LR.FL.P311CCa), X860 (LR.SP.P311CCa), X862 (LR.SP.P311CCa) and X864 (LR.SP.P311CCa) Multi-Function Printers and InfoPrint 1940 MT-Model 4570-gh1, gh2, gt1, gt2 (LR.BR.P311CCa), 1870 MT-Model 4567-gh1, gh2, gt1, gt2 (LR.MN.P311CCa), 1880 MT-Model 4568-gs1, gs2, gf1, gf2, gb1, gb2, g11, g12, g21, g22, g31, g32 (LR.MN.P311CCa), Color 1866 MT-Model 4915-gd1, gd2, gt1, gt2 (LR.FL.P311CCa), 1948 MT-Model 4857-g01, g02, g11, g12 (LR.SP.P311CCa), 1968 MT-Model 4858-gt1, gt2, g21, g22 (LR.SP.P311CCa) and 1988 MT-Model 4859-gt1, gt2, g31, g32 (LR.SP.P311CCa) Multi-Function Printers were judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1. The COACT, Inc. CAFE Lab determined that the evaluation assurance level (EAL) for the Lexmark X466 (LR.BR.P311CCa), X656 (LR.MN.P311CCa), X658 (LR.MN.P311CCa), X738 (LR.FL.P311CCa), X860 (LR.SP.P311CCa), X862 (LR.SP.P311CCa) and X864 (LR.SP.P311CCa) Multi-Function Printers and InfoPrint 1940 MT-Model 4570-gh1, gh2, gt1, gt2 (LR.BR.P311CCa), 1870 MT-Model 4567-gh1, gh2, gt1, gt2 (LR.MN.P311CCa), 1880 MT-Model 4568-gs1, gs2, gf1, gf2, gb1, gb2, g11, g12, g21, g22, g31, g32 (LR.MN.P311CCa), Color 1866 MT-Model 4915-gd1, gd2, gt1, gt2 (LR.FL.P311CCa), 1948 MT-Model 4857-g01, g02, g11, g12 (LR.SP.P311CCa), 1968 MT-Model 4858-gt1, gt2, g21, g22 (LR.SP.P311CCa) and 1988 MT-Model 4859-gt1, gt2, g31, g32 (LR.SP.P311CCa) Multi-Function Printers is EAL 3+.&nbsp;&nbsp;&nbsp; The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.</p>\r\n<p>The evaluation was completed in February 2011. Results of the evaluation and associated validation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report.</p>","environmental_strengths":"<p>The TOE&rsquo;s Security Functions are:</p>\r\n<p><strong>Audit Generation</strong> - The TOE generates audit event records for security-relevant events and transmits them to a remote IT system using the syslog protocol.</p>\r\n<p><strong>Identification and Authentication</strong> - The TOE supports I&amp;A with a per-user selection of internal accounts (processed by the TOE) or integration with an external LDAP server (in the operational environment).&nbsp; PKI authentication may also be specified, in which case all authentication must use PKI.&nbsp; A Backup Password mechanism may also be enabled.</p>\r\n<p><strong>Access Controls</strong> - Access controls configured for functions (e.g. fax usage) and menu access are enforced by the TOE.</p>\r\n<p><strong>Management</strong> - Through the touch panel, authorized administrators may configure access controls and perform other TOE management functions.</p>\r\n<p><strong>Operator Panel Lockout</strong> - Authorized users may lock and unlock the touch panel.&nbsp; When the touch panel is locked, print jobs are still accepted but they are queued on the disk drive until the touch panel is unlocked.</p>\r\n<p><strong>Fax Separation</strong> - The TOE ensures that only fax traffic is sent or received via the attached phone line.&nbsp; Incoming traffic is processed as fax data only; no management access or other data access is permitted.&nbsp; In the evaluated configuration, the only source for outgoing faxes is the scanner.</p>\r\n<p><strong>Hard Disk Encryption</strong> - All use data submitted to the TOE and stored on the hard disk is encrypted to protect its confidentiality in the event the hard drive was to be removed from the TOE.</p>\r\n<p><strong>Disk Wiping</strong> - In the evaluated configuration, the TOE automatically overwrites disk blocks used to store user data as soon as the data is no longer required.&nbsp; The mechanism used to perform the overwrite conforms with NIST SP800-88, and the DSS \"Clearing and Sanitization Matrix\" (C&amp;SM) available at <a href=\"http://www.sdisac.com/clearing_and_sanitization_matrix.doc\">http://www.sdisac.com/clearing_and_sanitization_matrix.doc</a>.</p>\r\n<p><strong>Secure Communication</strong> - The TOE protects the confidentiality and integrity of all information exchanged over the attached network by using IPSec with ESP for all network communication.</p>\r\n<p><strong>Self Test</strong> - During initial start-up, the TOE performs self tests on its hardware components and the integrity of the building blocks and security templates</p>","features":[]}