Check: SRG-MPOL-081
Mobile Policy SRG:
SRG-MPOL-081
(in version v1 r2)
Title
The organization must execute its incident response plan or applicable Standard Operating Procedure (SOP) when a CMD is reported lost or stolen. (Cat III impact)
Discussion
If procedures for lost or stolen CMDs are not followed, it is more likely that an adversary could obtain the device and use it to access DoD networks or otherwise compromise DoD information systems and data.
Check Content
Determine if any site mobile devices were reported lost or stolen within the previous 24 months. If yes, review written records, incident reports, and/or after action reports and determine if required procedures were followed. If the site had a lost or stolen mobile device within the previous 24 months and required procedures were not followed, this is a finding.
Fix Text
Follow required actions when a CMD is reported lost or stolen.
Additional Identifiers
Rule ID:
Vulnerability ID: V-35999
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000836 |
The organization reports security incident information to organization-defined authorities. |
Controls
Number | Title |
---|---|
IR-6 |
Incident Reporting |