Check: WIR-SPP-005
Commercial Mobile Device (CMD) Policy STIG (STIG):
WIR-SPP-005
(in version v2 r5)
Title
Mobile operating system (OS) based CMDs and systems must not be used to send, receive, store, or process classified messages unless specifically approved by NSA for such purposes and NSA approved transmission and storage methods are used. (Cat I impact)
Discussion
DoDD 8100.2 states wireless devices will not be used for classified data unless approved for such use. Classified data could be exposed to unauthorized personnel.
Check Content
Interview the ISSO. Verify written policy and training material exists (or requirement is listed on a signed user agreement) stating if and when CMDs can be used to transmit classified information. If written policy or training material does not exist, stating if and when CMDs can be used to receive, transmit, or process classified information, this is a finding.
Fix Text
Publish written policy or training material stating if and when CMDs can be used to process, send, or receive classified information.
Additional Identifiers
Rule ID: SV-30697r5_rule
Vulnerability ID: V-24960
Group Title: Classified data on CMDs
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |