Check: BBCP-00-013300
BlackBerry CylancePROTECT Mobile for UEM STIG:
BBCP-00-013300
(in version v1 r2)
Title
CylancePROTECT Mobile must be configured with the following Android security patch compliance and hardware certificate attestation controls: -"Android hardware attestation frequency" = 6 hours -"Device grace period" = 0 hours -"Challenge frequency for noncompliant devices" = 6 hours. (Cat II impact)
Discussion
The required application configurations will ensure that the minimum security baseline of the system is maintained to limit exposure of sensitive data and unauthorized access to the mobile device.
Check Content
Verify the following Android security patch compliance and hardware certificate attestation controls are enabled for CylancePROTECT Mobile: -"Android hardware attestation frequency" = 6 hours. -"Device grace period" = 3 days (72 hours). -"Challenge frequency for noncompliant devices = 1 day (24 hours). 1. Log on to the BlackBerry UEM console. 2. In the management console, click Settings >> General Settings >> Attestation. 3. In the "Android hardware attestation frequency" section, select verify "Enable hardware patch level attestation challenges for Android devices" is selected. 4. In the "Challenge frequency" drop-down list, verify the device attestation response is set to "1 day" (24 hours). 5. In the "Device grace period drop-down" list, verify the grace period is set to "3 days" (72 hours). 6. In the "Challenge frequency for noncompliant devices" field, verify the frequency UEM tests the integrity of devices that are not currently in compliance is set to "6 hours". If required Android security patch compliance and hardware certificate attestation controls are not enabled, this is a finding.
Fix Text
Configure the following Android security patch compliance and hardware certificate attestation controls: -"Android hardware attestation frequency" = 6 hours. -"Device grace period" = 3 days (72 hours). -"Challenge frequency for noncompliant devices" = 1 day (24 hours). 1. Log on to the BlackBerry UEM console. 2. In the management console, click Settings >> General Settings >> Attestation. 3. In the "Android hardware attestation frequency" section, select "Enable hardware patch level attestation challenges for Android devices" checkbox. 4. in the "Challenge frequency" drop-down list, set the device must return an attestation response to "1 day" (24 hours). 5. In the Device grace period drop-down list, set the grace period to "3 days" (72 hours). 6. In the Challenge frequency for noncompliant devices field, set how often UEM tests the integrity of devices that are not currently in compliance to "6 hours". 7. Click "Save".
Additional Identifiers
Rule ID: SV-257267r940014_rule
Vulnerability ID: V-257267
Group Title: SRG-APP-000516-AS-000237
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |