As you said this security expert is making sure that the 3300 only hands out IP addresses to Mitel phones, of course out of the box it will handle requests from all equipement request DHCP.
There is some programming on the 3300 you can do on the DHCP setting to only allow the 3300 to distribute IP addresses to mitel phones. It is as follows: (Copied from MOL)
'In order to prevent any other device except a Mitel IP Phone from getting an IP from the Mitel DHCP server, follow these steps
1. Give your IP Address Range the following name: ipphone.mitel.com
2. Enable the Client's class ID must match name option in the IP Range.
This causes the DHCP server to ignore all non-mitel IP Phone requests for an IP address. Please note that controller must be running 7.0 software or higher. As well if any new phones are added, then this option needs to be turned off until they upgrade their flash for the first time.'