Check: SRG-MPOL-070
Mobile Policy SRG:
SRG-MPOL-070
(in version v1 r2)
Title
An authorization process must be developed and published that states the process to obtain approval before CMDs can connect to the organizations information system(s). (Cat II impact)
Discussion
In order to protect their information systems, organizations must have a process in place ensuring mobile devices adhere to implementation guidance, meet published usage restrictions, and are processed through an authorization process prior to connecting to the information system(s). Lacking such a process, organizations will experience an array of unauthorized mobile devices, with a myriad of configuration settings and no usage restrictions, connecting to their information systems. Such an environment would be unmanageable and could result in unauthorized access to, modification of, or destruction of sensitive or classified data.
Check Content
Review the organization's access control and security policy and procedures addressing access control and authorization process for portable and mobile devices. Ensure the organization has developed and published an authorization process to be performed on each mobile device before the device can connect to the organization's information system(s). This authorization process will ensure the mobile device complies with all organization-published usage restrictions and implementation guidance. If an authorization process has not been developed and published, this is a finding.
Fix Text
Develop and publish an authorization process to be performed on each mobile device before the device can connect to the organization's information system(s).
Additional Identifiers
Rule ID:
Vulnerability ID: V-35988
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000084 |
The organization authorizes connection of mobile devices to organizational information systems. |
Controls
Number | Title |
---|---|
AC-19 |
Access Control For Mobile Devices |