Check: SRG-MPOL-078
Mobile Policy SRG:
SRG-MPOL-078
(in version v1 r2)
Title
The organization must ensure the MDM server administrator receives required training annually. (Cat III impact)
Discussion
The security posture of the MDM server could be compromised if the administrator is not trained to follow required procedures.
Check Content
Verify the MDM server administrator(s) has received annual required training. The site should document when the training was completed. The MDM server administrator must be trained on the following requirements: -Administrative service accounts will not be used to log into the MDM server or any server service. -Activation passwords or PINs will consist of a pseudo-random pattern of at least eight characters consisting of at least two letters and two numbers. A new activation password must be selected each time one is assigned (e.g., the same password cannot be used for all users or for a group of users). - User and group accounts on the CMD management server will always be assigned a STIG-compliant security/IT policy. If the MDM server admin did not receive required training annually, this is a finding.
Fix Text
Develop and publish policy mandating the MDM administrator completes and documents his/her training annually.
Additional Identifiers
Rule ID:
Vulnerability ID: V-35996
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001479 |
The organization provides refresher security awareness training to all information system users (including managers, senior executives, and contractors) in accordance with the organization-defined frequency. |
Controls
Number | Title |
---|---|
AT-2 |
Security Awareness Training |