STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 1 hour ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Multifunction Device and Network Printers Security Technical Implemetation Guide

V-6794

CAT II (Medium)

A MFD or printer is not configured to restrict jobs to those from print spoolers.

Rule ID

SV-7019r3_rule

STIG

Multifunction Device and Network Printers Security Technical Implemetation Guide

Version

V2R15

CCIs

None

Discussion

If MFDs or printers are not restricted to accept print jobs only from print spoolers that authenticate the user and log the job, a denial of service can be created by the MFD or printer accepting one or more large print jobs from an unauthorized user.<br /><br />The SA will ensure MFDs and printers are configured to restrict jobs only to print spoolers, not directly from users.<br /><br />Mobile device print jobs must be sent to a print spooler, they must not be sent directly from a mobile device to a MFD or printer that supports direct wireless printing (e.g., AirPrint, Wi-Fi Direct, etc.).<br /><br />The configuration is accomplished by restricting access, by IP, to those of the print spooler and SAs. If supported, IP restriction is accomplished on the device, or if not supported, by placing the device behind a firewall, switch or router with an appropriate discretionary access control list.<br />

Check Content

The reviewer will, with the assistance of the SA, verify that MFDs and printers are configured to restrict jobs only to print spoolers, not directly from users.<br /><br />If print jobs are sent directly to the MFD or printer, this is a finding.<br /><br />If direct wireless printing (e.g., AirPrint, Wi-Fi Direct, etc.), is enabled on the MFD or printer, this is a finding.

Fix Text

Reconfigure the device to restrict access, by IP, to those of the print spoolers and SAs.  If the device does not support this functionality, place the device behind a firewall, switch or router with an appropriate discretionary access control list. Disable direct wireless printing on the MFD or printer.