Insider Threat Matrix™Insider Threat Matrix™

Browser Print Restriction

Organizations should restrict browser-native print functionality within sensitive web applications, internal portals, administrative consoles, reporting platforms, and other browser-delivered tools where printing is not required for an approved business purpose.

 

Browser printing can allow a subject to collect information without using the application’s normal download or export functions. The subject may use the browser print menu, keyboard shortcuts, print preview, print-to-PDF, a physical printer, or another virtual printer to convert displayed content into a consolidated and portable output.

 

The control should ensure that browser printing cannot produce a usable unauthorized copy of protected information. Depending on operational requirements, organizations should:

  • Block browser print and print preview for designated applications, pages, records, or data classifications.
  • Prevent protected content from appearing in physical print output, print-to-PDF output, or output sent to other virtual printers.
  • Permit controlled printing only where required, with protected content removed, masked, redacted, limited to approved fields, or replaced with a blank page or access-denied notice.
  • Prevent alternate printable views, report-rendering endpoints, or document-generation routes from reproducing the same protected information.
  • Record attempted and completed browser print actions, including the subject identity, application, page or record accessed, timestamp, requested output method, and control outcome.

 

The restriction should be enforced through the web application, enterprise-managed browser, browser extension, browser security platform, or remote browser isolation service. Hiding a print button or suppressing a single keyboard shortcut is insufficient where the browser or application can still render the content through another print path.

Sections

ID Name Description
ME014Printing

A subject has the ability to print documents and other files.

IF006Unauthorized Printing of Documents

A subject exfiltrates information by printing it to paper or other physical medium.

IF006.002Printing of Documents with Work Printer

A subject prints a document using a printer owned by the organization, with the intent to physically exfiltrate the information.

IF006.001Printing of Documents with Personal Printer

A subject prints a document using a printer they own, physically exfiltrating the information.

ME014.001External Printing

A subject has the ability to print documents and other files with a printer outside of the organisation’s control.