Check: SRG-APP-000273-MAPP-NA
Mobile Application SRG:
SRG-APP-000273-MAPP-NA
(in version v1 r1)
Title
The application must prevent non-privileged users from circumventing malicious code protection capabilities. (Cat II impact)
Discussion
Malicious code protection software must be protected so as to prevent a non-privileged user or malicious piece of software from disabling the protection mechanism. A common tactic of malware is to identify the type of malicious code protection software running on the system and deactivate it. Malicious code includes, viruses, worms, Trojan horses, and Spyware. Examples include the capability for non-administrative user's to turn off or otherwise disable anti-virus. Rationale for non-applicability: Malicious code protections are implemented by the mobile operating system in conjunction with an MDM. Mobile applications within the scope of the SRG have no relationship to this functionality.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46994r1_rule
Vulnerability ID: V-35707
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001248 |
The information system prevents non-privileged users from circumventing malicious code protection capabilities. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |