Check: SRG-MPOL-063
Mobile Policy SRG:
SRG-MPOL-063
(in version v1 r2)
Title
Develop policy that states CMD software updates must only originate from DoD approved sources. (Cat II impact)
Discussion
Users must not accept over-the-air (OTA) wireless software updates from the wireless carrier or other non-DoD sources unless the updates have been tested and DoD approved. Unauthorized/unapproved software updates could include malware or cause a degradation of the security posture of the CMD and DoD network infrastructure. All software updates should be reviewed and/or tested by the CMD system administrator and originate from an approved DoD source. Wireless software updates should be pushed from the CMD management server, when this feature is available. Otherwise, the site administrator should verify the non-DoD source of the update has been approved by IT management.
Check Content
Review the site's procedure/policy on software updates for CMDs and ensure it includes a requirement for updates to be obtained from a DoD approved source. Verify the site CMD handheld administrator and the CMD management server administrator are aware of the requirement. Determine what procedures are used at the site for installing software updates on site-managed CMDs. If the site does not have procedures in place for users to down-load software updates from only a DoD approved source, this is a finding.
Fix Text
Develop policy requiring CMD software updates originate from DoD approved sources.
Additional Identifiers
Rule ID:
Vulnerability ID: V-35981
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000083 |
The organization establishes implementation guidance for organization-controlled mobile devices. |
Controls
Number | Title |
---|---|
AC-19 |
Access Control For Mobile Devices |