HP Enterprise printers and scanners - Imaging and Printing Security Best Practices (white paper)

Intercepting print jobs, copy jobs, fax jobs, or digital send jobs (such as email).
You can minimize the risks of information disclosure in the following ways:
Enable IPsec to protect data in transit.
Use hardware encryption to protect data at rest. Some devices may include an encrypted disk. If not, you can add an HP
Secure Hard Disk accessory to protect data stored on your MFP. (Look for this product at hp.com or contact your HP
product supplier).
Close unused ports and protocols.
Configure all possible password settings.
Configure authentication.
Configure SNMPv3 for Web Jetadmin.
Disable viewing of job information on the EWS information tab
Denial of Service
Denial of service is any type of interference with normal use of an MFP. This can include any of the following:
Canceling or pausing the print jobs of others
Turning off the MFP remotely
Disconnecting power to the MFP
Removing the MFP formatter board
Disconnecting the MFP from the network
Causing interference with network communication to the MFP
Changing the network location of the MFP
Causing an error state that interrupts service
Changing access configurations
Here are some methods of minimizing opportunities for denial of service on an MFP:
Lock the control panel by configuring Access Controls.
Lock EWS configuration settings.
Close unused ports and protocols.
Disable controls such as the Job Cancel button and the Go button.
Enable the resume feature to allow the MFP to resume operations after an error state.
Configure Job Timeout.
Control physical access to the MFP.
Lock physical access to removable hardware.
Elevation of Privilege
Elevation of privilege is any method of upgrading authorized access to include unauthorized access. This can be any of the
following:
Non-administrators changing settings to get administrator privileges
Unauthorized use of management software to provide access for other unauthorized users
Using management software to bypass job accounting functions
Here are some methods of minimizing opportunities for elevation of privilege: