Check: SRG-MPOL-038
Mobile Policy SRG:
SRG-MPOL-038
(in version v1 r2)
Title
The organization must not permit operation of wireless devices in areas where classified information is electronically stored, processed, or transmitted unless operation is in accordance with DAA-approved CTTA restrictions at the site. (Cat II impact)
Discussion
The operation of electronic equipment and emanations must be controlled in and around areas where sensitive information is kept or processed. Ensure wireless devices are not operated in areas where classified information is electronically stored, processed, or transmitted unless: - Approved by the DAA in consultation with the Certified TEMPEST Technical Authority (CTTA). - The wireless equipment is separated from the classified data equipment at the minimum distance determined by the CTTA, and appropriate countermeasures, as determined by the CTTA, are implemented.
Check Content
Review documentation and verify the following. Ask for documentation showing the CTTA was consulted about operation and placement of wireless devices. Acceptable proof would be the signature or initials of the CTTA on the architecture diagram or other evidence of coordination. In accordance with DoD policy, the CTTA must have a written separation policy for each classified area; review written policies, training material, or user agreements to see if wireless usage in these areas is addressed; and verify proper procedures for wireless device use in classified areas is addressed in training programs. If any of the following are identified, this is a finding: - CTTA has not designated a separation distance in writing. - DAA has not coordinated with the CTTA. - Users are not trained or made aware (using signage or user agreement) of procedures for wireless device usage in and around classified processing areas. - Site does not have a written procedure prohibiting the use of wireless devices in areas where classified data processing occurs.
Fix Text
Do not permit operation of wireless devices in areas where classified information is electronically stored, processed, or transmitted unless operation is in accordance with DAA-approved CTTA restrictions at the site.
Additional Identifiers
Rule ID:
Vulnerability ID: V-35956
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001330 |
The organization prohibits the use of unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official. |
CCI-001333 |
The organization prohibits use of internal or external modems or wireless interfaces within unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information. |
Controls
Number | Title |
---|---|
AC-19 (4) |
Restrictions For Classified Information |