{"product_id":10456,"v_id":10456,"product_name":"Lexmark X548, XS548, X792, XS796, X925, XS925, X950, X952, X954, XS955 and 6500e Scanner (with T650, T652, T654, or T656 Printer) Multi-Function Printers","certification_status":"Not Certified","certification_date":"2012-05-29T00:05:00Z","tech_type":"Multi Function Device","vendor_id":{"name":"Lexmark International, Inc.","website":"http://www.lexmark.com"},"vendor_poc":"Graydon Dodson","vendor_phone":"859.232.6483","vendor_email":"gdodson@lexmark.com","assigned_lab":{"cctl_name":"COACT, Inc. Labs"},"product_description":"<p><strong>The TOE provides the following functions related to Multi-Function Printers (MFP):</strong></p>\r\n<p><strong>A)&nbsp;&nbsp;&nbsp; </strong><strong>Printing &ndash; producing a hardcopy document from its electronic form</strong></p>\r\n<p><strong>B)&nbsp;&nbsp;&nbsp; </strong><strong>Scanning &ndash; producing an electronic document from its hardcopy form</strong></p>\r\n<p><strong>C)&nbsp;&nbsp;&nbsp; </strong><strong>Copying &ndash; duplicating a hardcopy document</strong></p>\r\n<p><strong>D)&nbsp;&nbsp;&nbsp; </strong><strong>Faxing &ndash; scanning documents in hardcopy form and transmitting them in electronic form over telephone lines, and receiving documents in electronic form over telephone lines and printing them in hardcopy form</strong></p>\r\n<p><strong>The Lexmark 6500e Scanner is integrated with a T65x monochrome printer to provide a complete MFP. The scanner unit provides the touch panel, original document handler, fax interface, and network interface. The printer unit provides the print engine and its only external connection is to the scanner unit. The TOE includes the hardware and firmware in both the scanner and printer units. All of the other models included in the evaluation (X548, XS548, X792, XS796, X925, XS925, X950, X952, X954, and XS955) are complete MFPs in a single unit.</strong></p>\r\n<p><strong>All of the MFPs included in this evaluation provide the same security functionality. Their differences are in the speed of printing and support for color operations.</strong></p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the Lexmark X548 (LHS2.VK.P244aCC), XS548 (LHS2.VK.P244aCC), X792 (LHS2.MR.P244aCC), XS796 (LHS2.MR.P244aCC), X925 (LHS2.HK.P244aCC), XS925 (LHS2.HK.P244aCC), X950 (LHS2.TQ.P244aCC), X952 (LHS2.TQ.P244aCC), X954 (LHS2.TQ.P244aCC), XS955 (LHS2.TQ.P244aCC) and 6500e Scanner (LHS2.JR.P244dCC) (with T650 (LHS2.JR.P244dCC), T652 (LHS2.JR.P244dCC), or T654 (LHS2.JR.P244dCC) Printer) Multi-Function Printers meet the security requirements contained in the Security Target.</p>\r\n<p>The criteria against which the Lexmark X548 (LHS2.VK.P244aCC), XS548 (LHS2.VK.P244aCC), X792 (LHS2.MR.P244aCC), XS796 (LHS2.MR.P244aCC), X925 (LHS2.HK.P244aCC), XS925 (LHS2.HK.P244aCC), X950 (LHS2.TQ.P244aCC), X952 (LHS2.TQ.P244aCC), X954 (LHS2.TQ.P244aCC), XS955 (LHS2.TQ.P244aCC) and 6500e Scanner (LHS2.JR.P244dCC) (with T650 (LHS2.JR.P244dCC), T652 (LHS2.JR.P244dCC), or T654 (LHS2.JR.P244dCC) Printer) Multi-Function Printers was judged is described in the Common Criteria for Information Technology Security Evaluation, Version 3.1. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1.</p>\r\n<p>The COACT, Inc. CAFE Lab determined that the evaluation assurance level (EAL) for the Lexmark X548 (LHS2.VK.P244aCC), XS548 (LHS2.VK.P244aCC), X792 (LHS2.MR.P244aCC), XS796 (LHS2.MR.P244aCC), X925 (LHS2.HK.P244aCC), XS925 (LHS2.HK.P244aCC), X950 (LHS2.TQ.P244aCC), X952 (LHS2.TQ.P244aCC), X954 (LHS2.TQ.P244aCC), XS955 (LHS2.TQ.P244aCC) and 6500e Scanner (LHS2.JR.P244dCC) (with T650 (LHS2.JR.P244dCC), T652 (LHS2.JR.P244dCC), or T654 (LHS2.JR.P244dCC) Printer) Multi-Function Printers is EAL 2+.&nbsp;&nbsp; The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.</p>\r\n<p>A team of Validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by the COACT, Inc. CAFE Lab. The evaluation was completed in January 2012. &nbsp;</p>\r\n<p>Results of the evaluation and associated validation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report.</p>","environmental_strengths":"<p>The TOE&rsquo;s Security Functions are:</p>\r\n<p>A) <strong>Audit Generation</strong> - The TOE generates audit event records for security-relevant events and transmits them to a remote IT system using the syslog protocol.</p>\r\n<p>B) <strong>Identification and Authentication</strong> - The TOE supports I&amp;A with a per-user selection of internal accounts (processed by the TOE) or integration with an external LDAP server (in the operational environment).&nbsp; PKI authentication may also be specified, in which case all authentication must use PKI.&nbsp; A Backup Password mechanism may also be enabled.</p>\r\n<p>C) <strong>Access Controls</strong> - Access controls configured for functions (e.g. fax usage) and menu access are enforced by the TOE.</p>\r\n<p>D) <strong>Management</strong> - Through web browser sessions, authorized administrators may configure access controls and perform other TOE management functions.</p>\r\n<p>E) <strong>Operator Panel Lockout</strong> - Authorized users may lock and unlock the touch panel.&nbsp; When the touch panel is locked, print jobs are still accepted but they are queued on the disk drive until the touch panel is unlocked.</p>\r\n<p>F) <strong>Fax Separation</strong> - The TOE ensures that only fax traffic is sent or received via the attached phone line.&nbsp; Incoming traffic is processed as fax data only; no management access or other data access is permitted.&nbsp; In the evaluated configuration, the only source for outgoing faxes is the scanner.</p>\r\n<p>G) <strong>Hard Disk Encryption</strong> - All user data submitted to the TOE and stored on the hard disk is encrypted to protect its confidentiality in the event the hard drive was is removed from the TOE.</p>\r\n<p>H) <strong>Disk Wiping</strong> - In the evaluated configuration, the TOE automatically overwrites disk blocks used to store user data as soon as the data is no longer required.&nbsp; The mechanism used to perform the overwrite function complies with NIST SP800-88, and the DSS \"Clearing and Sanitization Matrix\" (C&amp;SM) available at <a href=\"http://www.sdisac.com/clearing_and_sanitization_matrix.doc\">http://www.sdisac.com/clearing_and_sanitization_matrix.doc</a>.</p>\r\n<p>I) <strong>Secure Communication</strong> - The TOE protects the confidentiality and integrity of all information exchanged over the attached network by using IPSec with ESP for all network communication.</p>\r\n<p>J) <strong>Self Test</strong> - During initial start-up, the TOE performs self tests on its hardware components and the integrity of the building blocks and security templates.</p>","features":[]}