Check: WIR-SPP-012
General Mobile Device (Non-Sensitive-Non-Network-Connected):
WIR-SPP-012
(in version v1 r1)
Title
Smartphones and tablets classified as non-enterprise activated must not be connected to a DoD network. (Cat I impact)
Discussion
Some smartphones and tablets, including some models of Windows 7, Android, iOS, and BlackBerry smartphones and tablets, are not authorized to connect to DoD networks or to DoD PCs that will be connected to DoD networks, because they do not have required security controls. There is a high risk of introducing malware on a DoD network if these types of devices are connected to a DoD network.
Check Content
Smartphones and tablets classified as non-enterprise activated are not authorized to connect to a DoD networks. Examples of unauthorized DoD network connections include: -Connecting the mobile device to a DoD network interface device (switch, router, Wi-Fi access point, etc.). Allowed exception: the device can be connected to a DoD managed Internet-Gateway-only connected Wi-Fi access point (AP) (see the Wireless STIG for more information). -Connecting the mobile device to a DoD PC that is authorized to connect to a DoD network. - Managing the mobile device from a DoD network connected Mobile Device Management (MDM) server. -Connecting the mobile device to a web server located on a DoD network, unless the server is available to the general public. -Connecting the mobile device to a DoD email system. Check Procedures: Interview the IAO and 2-3 users who are using mobile OS devices that are managed by the site, which are not authorized to connect to DoD networks. Verify written policy and training material exists (or requirement is listed on a signed user agreement) stating mobile OS devices must not be connected to a DoD network, unless authorized to do so. Verify users are aware of the requirement. Mark as a finding if written policy or training material does not exist or users are not aware of the requirement.
Fix Text
Do not connect smartphones and tablets classified as non-enterprise activated to DoD networks.
Additional Identifiers
Rule ID:
Vulnerability ID: V-30413
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |