首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 ISO/IEC 7184:2024
到馆阅读
收藏跟踪
购买正版
Office equipment — Security requirements for hard copy devices (HCDs) — Part 1: Definition of the basic requirements 办公设备硬拷贝设备的安全要求第1部分:基本要求的定义
发布日期: 2024-02-02
本文件定义了保护硬拷贝设备(HCD)的基本安全要求,包括识别和认证、安全管理、软件更新、现场可更换非易失性存储数据保护、网络数据保护和公共交换电话网(PSTN)传真-网络分离。 可应用于打印机、扫描仪、传真机、数码复印机、数码多功能一体机等具有网络功能的办公设备,特别适合小型办公和家庭办公用户。 本文档假设了一个小型的、私有的信息处理环境,其中大多数安全元素由物理环境提供。在这样的环境中,通常通过限制对HCD的物理访问并将其连接到受公共互联网保护的LAN,假定在物理上和逻辑上免受源自该环境外部的威胁。小型办公室或家庭办公室是这种环境的典型例子。 请注意,本文档中概述的要求并不打算取代现有的硬拷贝设备通用标准认证,后者确保了企业环境的最低安全要求。例如,审计数据生成、自检能力和关键材料保护等共同标准认证所需的方面没有得到充分解决。

This document defines basic security requirements for the protection of hard copy devices (HCDs) including identification and authentication, security management, software update, field-replaceable nonvolatile storage data protection, network data protection and public switched telephone network (PSTN) fax-network separation.

It can be applied to office equipment with network functions including printers, scanners, fax machines, digital copiers, and digital multi-function machines, specifically for small office and home office users.

This document assumes a small, private information processing environment in which most elements of security are provided by the physical environment. In such an environment is assumed to be physically and logically protected from threats originating from outside of that environment, typically by limiting physical access to the HCD and connecting it to a LAN that is protected from the public Internet. A small office or home office would be a typical example of this environment.

Please note that the requirements outlined in this document are not intended to replace the existing Common Criteria Certification for hardcopy devices which ensure the minimum-security requirements for enterprise environment. For example, aspects being required in Common Criteria Certification such as audit data generation, self-test capabilities, and protection of key material are not adequately addressed.

分类信息
关联关系
研制信息
归口单位: ISO/IEC JTC 1/SC 28
相似标准/计划/法规