BlackBerry CylancePROTECT Mobile for UEM STIG Version Comparison
BlackBerry CylancePROTECT Mobile for UEM Security Technical Implementation Guide
Comparison
There are 1 differences between versions v1 r1 (July 4, 2023) (the "left" version) and v1 r2 (Jan. 24, 2024) (the "right" version).
Check BBCP-00-013300 was changed between these two versions. Green, underlined text was added, red, struck-out text was removed.
The regular view of the left check and right check may be easier to read.
Text Differences
Title
CylancePROTECT Mobile must be configured with the following Android security patch compliance and hardware certificate attestation controls: -"Android hardware attestation frequency" = 6 hours -"Device grace period" = 0 hours -"Challenge frequency for noncompliant devices" = 6 hours.
Check Content
Verify the following Android security patch compliance and hardware certificate attestation controls are enabled for CylancePROTECT Mobile: -"Android hardware attestation frequency" = 6 hours. -"Device grace period" = 0 3 days (72 hours. -"Challenge hours). -"Challenge frequency for noncompliant devices = 6 1 day (24 hours. 1. hours). 1. Log on to the BlackBerry UEM console. 2. In the management console, click Settings >> General Settings >> Attestation. 3. In the "Android hardware attestation frequency" section, select verify "Enable hardware patch level attestation challenges for Android devices" is selected. 4. In the "Challenge frequency" drop-down list, verify the device attestation response is set to "6 "1 day" (24 hours". 5. hours). 5. In the "Device grace period drop-down" list, verify the grace period is set to "3 days" (72 hours). 6. "0 hours" (no grace period). 6. In the "Challenge frequency for noncompliant devices" field, verify the frequency UEM tests the integrity of devices that are not currently in compliance is set to "6 hours". If required Android security patch compliance and hardware certificate attestation controls are not enabled, this is a finding.
Discussion
The required application configurations will ensure that the minimum security baseline of the system is maintained to limit exposure of sensitive data and unauthorized access to the mobile device.
Fix
Configure the following Android security patch compliance and hardware certificate attestation controls: -"Android hardware attestation frequency" = 6 hours. -"Device grace period" = 0 3 days (72 hours. -"Challenge hours). -"Challenge frequency for noncompliant devices" = 6 1 day (24 hours. 1. hours). 1. Log on to the BlackBerry UEM console. 2. In the management console, click Settings >> General Settings >> Attestation. 3. In the "Android hardware attestation frequency" section, select "Enable hardware patch level attestation challenges for Android devices" checkbox. 4. in the "Challenge frequency" drop-down list, set the device must return an attestation response to "6 "1 day" (24 hours". 5. hours). 5. In the Device grace period drop-down list, set the grace period to "3 days" (72 hours). 6. "0 hours" (no grace period). 6. In the Challenge frequency for noncompliant devices field, set how often UEM tests the integrity of devices that are not currently in compliance to "6 hours". 7. Click "Save".