GB/T 29244-2024Cybersecurity technology - Security specification for office devices (English PDF)
网络安全技术 办公设备安全规范
Open the GB/T 29244-2024 preview as PDF
This is a limited preview
Buy now to download the full PDF (14 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
September 29, 2024
Implementation date
April 1, 2025
Scope
GB/T 29244-2024 is the English-translated version of 网络安全技术 办公设备安全规范.
GB/T 29244-2024 covers office devices - equipment that produces or processes electronic or other media documents, in practice machines combining one or more of the printing, scanning, fax and copying functions - and sets out the security function requirements, the security assurance requirements and the assessment methods that go with them. It applies to the procurement, assessment, maintenance and management of such devices, and equally to their security design, implementation and operation. The document works with two security levels, basic and enhanced, the level being decided by the strength of the security functions and the height of the assurance measures; Annex A grades the technical requirements and Annex B grades the assessment methods, in both cases separately for devices with a printing, scanning, copying or fax function. The security function requirements are grouped into identification and authentication, access control, firmware security, log recording and auditing, user data security, communication security, non-volatile storage security and configuration security. The security assurance requirements address what the device provider does during design and development, production and delivery, operation and maintenance, and supply chain management. Clause 7 gives the matching test or document check for every requirement.
Document preview — GB/T 29244-2024
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
- Replacing
- GB/T 29244-2012
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 1 Scope1
- 2 Normative references1
- 3 Terms and definitions1
- 4 Abbreviations2
- 5 General2
- 6 Security technical requirements2
- 6.1 Security function requirements2
- 6.2 Security assurance requirements4
- 7 Assessment methods6
- 7.1 Assessment methods for the security function requirements6
- 7.2 Assessment methods for the security assurance requirements8
- Annex A (normative) Classification of office devices and grading of the security technical requirements11
- Annex B (normative) Classification of office devices and grading of the assessment methods14
2 Normative references
Three documents are cited: GB/T 18336, Information technology - Security techniques - Evaluation criteria for IT security; GB/T 25069, Information security technology - Terminology; and GB/T 29829, Information security technology - Functionality and interface specification of cryptographic support platform for trusted computing.
Dated references apply in the cited edition only; undated references apply in their latest edition, including all amendments.
3 Terms and definitions
The terms defined in GB/T 18336 and GB/T 25069 apply, together with the eight terms below.
3.1 office device: device used to produce or process electronic or other media documents. Note: office devices are mainly devices having one or more of the printing, scanning, fax and copying functions.
3.2 administrator: user authorised to manage some or all parts of the office device.
3.3 user: entity, a person or an information technology entity, that operates the office device or interacts with it.
3.4 user data: data created by the user or for the user that does not affect the operation of the security functions of the office device. Note: user data includes user document data and user function data.
3.5 non-volatile storage: storage whose stored data is not lost when the power is switched off. Note: non-volatile storage mainly includes built-in or external hard disks, universal serial bus (USB) drives, secure digital (SD) cards and flash memory.
3.6 firmware: programs that implement interface communication, security functions, data parsing, image processing and engine control of the office device.
3.7 master control chip: integrated circuit chip, or set of chips, responsible for data parsing, image processing, job management and control of the print head, and outputting binary image data directly.
3.8 data control board: circuit board built into the office device that carries the master control chip and is responsible for the data control functions. Note: the data control functions include data communication, job allocation and management, job data parsing, image processing of print, copy and scan data, and output control of the binary image data.
4 Abbreviations
IP, Internet Protocol; MAC, Media Access Control; PIN, Personal Identification Number; SNMP, Simple Network Management Protocol.
5 General
The security technical requirements for office devices are made of security function requirements and security assurance requirements. The security function requirements state the security functions the device is to have. The security assurance requirements state the security measures the device provider is to take during the design, development, production, delivery, operation, maintenance and supply chain management of the device.
The document divides the security level of office devices into a basic level and an enhanced level. The strength of the security functions and the height of the security assurance requirements are the basis of that division. The grading of the security technical requirements follows Annex A and the grading of the assessment methods follows Annex B.
6.1 Security function requirements
6.1.1 Identification and authentication. The user identity is to be identified, and authenticated when device functions and security functions are performed. Session timeout locking is to be supported, together with a settable maximum number of authentication failures beyond which authentication by the user is restricted for a period or the account is locked. Where a default password exists, the user is to be allowed to change it and is to be prompted to do so.
6.1.2 Access control. Administrators and ordinary users are to be given the least access rights needed for their own tasks; authorisation management is to let the administrator grant rights to ordinary users; access to device functions and to user data is to be granted or refused according to an access control policy; an IP or MAC allow list is to be provided; execution of jobs through a PIN should be supported, with the job locked once the set maximum number of PIN failures is exceeded, and with a deletion mechanism applied when the device is switched off and restarted.
6.1.3 Firmware security. A firmware update management function is to be provided, the update being performed by the administrator where one exists and otherwise only after the separate consent of the user. Integrity and authenticity are to be verified before the update by digital signature, hash operation or an equivalent means, and the update stopped at once if verification fails. The firmware is not to contain malicious programs. Integrity and authenticity are to be checked automatically at start-up and work stopped at once if an anomaly is found. Where trusted verification is done by a trusted cryptographic module, that module is to meet GB/T 29829.
6.1.4 Log recording and auditing. Audit records are to be produced for the opening and closing of the audit function, the start or completion of device functions, use of the identification or authentication mechanism, changes of system time, firmware updates, replacement of chipped consumables, job data including but not limited to page and copy counts, and other events related to system security or defined as auditable. Each record is to carry at least the date and time of the event, the event type, the user identity and the result. Export of the records, for instance as an electronic file or a printed information report, is to be supported, the records are to be protected against unauthorised deletion, and, where no interface for sending records is provided, they are to be kept on the device for not less than six months.
6.1.5 User data security. User document data and the related temporary and cache files in the corresponding modules and in the driver are to be deleted automatically once the job is finished; measures are to ensure that a user can act only on their own document data; user data is not to be stored in the consumable chip, statistics on consumable use excepted; stored logs and configuration data are to be protected by measures including but not limited to encryption and integrity checking; where a fault or an error occurs and the user takes no action within a set time, user document data is to be deleted once the device returns to normal; automatic and manual clearing of residual information on consumables is to be provided.
6.1.6 Communication security. The device is to withstand common network attacks; ports, services and protocols unrelated to its functions are to be closed under the least authorisation principle; no covert channel is to exist; a function for closing ports, services and protocols is to be provided; the connection is to be terminated automatically after a prescribed silent period; a secure SNMP protocol is to be used by default; the confidentiality, integrity and availability of the communicated data are to be protected; the device and the driver are to recognise each other before job data is transferred; where a wireless communication module is present, a function to close it is to be provided and it is to be off by default, the note listing wireless local area network, Bluetooth and infrared modules among others; network sharing and remote management, where present, are likewise to be closable and off by default; non-repudiation should be provided.
6.1.7 Non-volatile storage security. Functions are to be provided for checking the integrity of the user data held in non-volatile storage and for deleting it. Where a built-in removable non-volatile memory exists, it is to use a public data storage structure and exchange data with its control system through a public protocol; the note names the file allocation table (FAT) and the extended file system (EXT) as public structures and the integrated drive electronics (IDE) interface, serial advanced technology attachment (SATA) and the peripheral component expansion interface (PCIe) as public protocols. Where external non-volatile storage is supported, the administrator is to be able to close it and it is to be off by default; an external non-volatile memory used for identity authentication is not to hold user data other than the authentication information.
6.1.8 Configuration security. A function for maintaining the security configuration is to be provided, with query and modification carried out by the administrator; a self-test function is to be provided that demonstrates the correct operation of all or part of the security functions; where an operation panel exists, panel locking is to be supported.
6.2 Security assurance requirements
6.2.1 Design and development. The provider is to identify the security risks of the design and development stages, set a security policy and take measures protecting the design and development of the key components; establish and apply a secure development process that reduces the risk of malicious code being planted and of vulnerabilities being introduced; place design and development documents under configuration management with a configuration list and authorised, controlled change; carry out security testing of the device, including the third-party software and hardware modules it uses, on its own, jointly or through a third party; repair security defects and vulnerabilities found during development and operate an emergency repair process for those not found at that stage; ensure consistency between the design and the implementation of the security functions; and possess the capability to design and develop key components such as the driver, the firmware and the data control board.
6.2.2 Production and delivery. The provider is to describe all user-related function modules and access interfaces, including but not limited to man-machine and debug interfaces; declare, through the user agreement, the user manual or a website notice, that no vulnerability, back door or trojan has been deliberately left or set in the device; state clearly the capacity of the non-volatile memory and of the writable area of the consumable chip together with the type and purpose of the data stored; state in the user manual all default user information and types with the corresponding authentication information; establish and apply a regular production and service delivery process with security checks and verification at the key steps; provide the user with measures for verifying the integrity of the delivered hardware and software; and provide guidance documents such as an operating manual covering the typical deployment environment and the security requirements it is to meet, the user roles and security responsibilities, the risk warnings and the emergency response measures.
6.2.3 Operation and maintenance. The provider is to establish and run an emergency response mechanism and process for the security defects and vulnerabilities that appear in service; establish and apply a user information protection system, deleting personal information on its own initiative or at the request of the user where the collection or use breaches the law or the agreement between the parties; not stop security maintenance within the agreed period, work within the authorisation given by the user, protect the data handled during maintenance against disclosure, tampering and damage, and not pass data to others or use it for purposes other than maintenance without the consent of the user; inform the user before an update of its content, including the changes, the related security risks and the countermeasures, obtain consent before applying it and allow the user to refuse it; take remedial measures at once when a defect or a vulnerability is found, including repair or a safe alternative, inform partners and users and report to the competent authorities; give advance notice of the handling operations and their possible effects before repair; provide methods or tools that let the user check the integrity and the authenticity of the origin of update packages; and protect user data against disclosure, tampering, damage and loss during maintenance.
6.2.4 Supply chain security. The provider is to declare that it will not set a back door in the device, will not use the convenience of supplying the device to obtain user data unlawfully or to control and manipulate user systems and devices, will not use the dependence of the user on the device to obtain improper advantage and will not force the user to update the device. Procurement channels are to be managed so that supply of the master control chip, engine, data control board, consumables and other key parts stays stable or diversified. Operation and maintenance material is to be supplied in Chinese and, where a secondary development mechanism exists, secondary development technical material as well; the note describes secondary development as the extension of functions carried out for the operation and maintenance of the device, with software development kits (SDK) and their material, or test tools, as its instruments. For known patents and other intellectual property owned or controlled by third parties and involved in research, development and manufacture, an authorisation of more than ten years, or one covering the market life of the device, is to be obtained where authorisation has been granted. The known third-party technologies used are to be declared and are not to be subject to interruption of supply of devices, master control chips, engines, firmware, print heads, scan heads, other components and materials for reasons of trade or service capability, nor to the stopping of software licensing, updates or technical support.
7 Assessment methods
Clause 7.1 gives the test for each security function requirement, in the same order as 6.1. The tests are practical: creating users and checking that duplicate identities are refused and that failed authentication blocks access; letting a session sit idle to see the lock take effect; setting an IP or MAC allow list and checking that only listed devices reach the machine; running a job through a PIN and checking the locking and the deletion behaviour after a restart; performing a firmware update whose signature or hash does not verify; scanning the firmware with two different malicious code detection tools; producing each auditable event and reading the records back; sending a job and inspecting the modules, the driver and the consumable for leftover data; probing ports, services, protocols and the covert channel declaration; exercising the integrity check and the deletion function of the non-volatile memory; and logging in with an administrator and with an ordinary account to see who can change the security configuration.
Clause 7.2 gives the checks for the security assurance requirements, which are carried out on the documents and evidence supplied by the provider: risk identification and security policy for design and development, the development management system and its application, configuration management of the documents, the security test report and its conclusion, the defect and vulnerability management system including the emergency repair process, the material showing consistency between the security functions and the implementation, and the evidence of design and development capability for the key components; then the interface and function module description, the declaration on back doors, the stated memory and chip capacities, the default account information in the manual, the production and delivery process, the integrity verification measures and the guidance documents; then the emergency response records, the user information protection records, the maintenance commitments and their scope, the update notice and the option to refuse it, the remediation process, the advance notice of repair operations, the verification tools for update packages and the user data protection measures; and finally the supply chain declarations, the channel management evidence, the Chinese language material, the intellectual property authorisation and the third-party technology declaration.
A Annex A (normative) Classification of office devices and grading of the security technical requirements
Annex A lists the security technical requirements for office devices having a printing, scanning, copying or fax function and states the minimum set of basic level and enhanced level requirements for each of those four classes. Four tables, A.1 to A.4, are given, each with one column for the basic level and one for the enhanced level; a dash means that the requirement does not apply at that level.
Table A.1, for devices with a printing function, sets the basic level at 6.1.3 a) and b) for firmware security, 6.1.5 a) and b) for user data security, 6.1.6 a) to c) for communication security, 6.1.7 a) and b) for non-volatile storage security, 6.2.1 a) to e) for design and development, 6.2.2 a) to d) for production and delivery, 6.2.3 a) to d) for operation and maintenance and 6.2.4 a) for supply chain security, with identification and authentication, access control, log recording and auditing and configuration security marked as not applicable. At the enhanced level all twelve requirements apply in full, that is 6.1.1 to 6.1.8 and 6.2.1 to 6.2.4.
Tables A.2, A.3 and A.4 grade the same twelve requirements for devices with a scanning, a copying and a fax function respectively, and are read the same way. They are narrower than Table A.1: for the scanning class identification and authentication, access control, log recording and auditing, communication security and configuration security stay outside both levels, while for the copying and the fax class only part of those become applicable at the enhanced level.
B Annex B (normative) Classification of office devices and grading of the assessment methods
Annex B mirrors Annex A. Following the requirements of Annex A, it lists in Tables B.1 to B.4 the assessment methods that correspond to the requirements applicable to devices with a printing, scanning, copying or fax function, again with a basic level column and an enhanced level column and with a dash for what does not apply.
The clause numbers cited are those of Clause 7 and they run parallel to the clause numbers of Clause 6 cited in Annex A: where Table A.1 cites 6.1.3 a) and b), Table B.1 cites 7.1.3 a) and b), and so on through the twelve requirements.
R Relationship to previous standards
The cover page carries the replacement note for two documents: GB/T 29244-2012, Information security technology - Basic security requirements for office devices, and GB/T 38558-2020, Information security technology - Security test methods for office devices. GB/T 29244-2012 is the one carried in the code field of the edition table; GB/T 38558-2020 is the second document withdrawn by this edition.
The foreword records the main technical changes against both: an overview clause was added (Clause 5); the terms and definitions were changed (Clause 3); firmware security requirements and their assessment methods were added (6.1.3 and 7.1.3); the security assurance requirements and their assessment methods were added (6.2 and 7.2); security auditing was renamed log recording and auditing (6.1.4); session was renamed communication security (6.1.6); data management was renamed user data security (6.1.5); and security attribute management was renamed configuration security (6.1.8).
The publication history states that GB/T 29244-2012 was first issued in 2012 and GB/T 38558-2020 first issued in 2020, and that the present document is the first revision.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 14 pages — is available in the English PDF.
Editions of GB/T 29244
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 29244-2024 | Cybersecurity technology - Security specification for office devices | current edition | Current |
| GB/T 29244-2012 | Cybersecurity technology - Security specification for office devices | previous edition | In force until 2025-04-01 |
This page sells the current edition, GB/T 29244-2024. Earlier editions are listed for reference only.
How to Buy GB/T 29244-2024
- 1Add to cart. Click the "Buy GB/T 29244-2024" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 29244-2024
$365.00