Check: WIR-SPP-003-02
Smartphone Policy:
WIR-SPP-003-02
(in versions v1 r8 through v1 r6)
Title
If a data spill (Classified Message Incident (CMI)) occurs on a wireless email device or system at a site, the site must follow required data spill procedures. (Cat I impact)
Discussion
If required procedures are not followed after a data spill, classified data could be exposed to unauthorized personnel.
Check Content
Detailed Policy Requirements: This requirement applies to mobile operating system (OS) smartphones and tablets. This requirement also applies to sensitive DoD information stored on mobile OS devices that are not authorized to connect to DoD networks or store/process sensitive DoD information. Sensitive DoD data or information is defined as any data/information that has not been approved for public release by the site/Command Public Affairs Officer (PAO). If a data spill occurs on a smartphone, the following actions must be completed: - The smartphone management server and email servers (i.e., Exchange, Oracle mail, etc.) are handled as classified systems until they are sanitized according to appropriate procedures. (See NSA/CSS Storage Device Declassification Manual 9-12 for sanitization procedures.) - The smartphone is handled as a classified device and destroyed according to DoD guidance for destroying classified equipment or sanitized as directed in Check WIR-SPP-003-01. Check Procedures: Interview the IAO. Determine if the site has had a data spill within the previous 24 months. If yes, review written records, incident reports, and/or after action reports and determine if required procedures were followed. Mark as a finding if the site had a data spill within the previous 24 months and required procedures were not followed.
Fix Text
If a data spill occurs on a wireless email device or system at a site, the site must follow required procedures.
Additional Identifiers
Rule ID: SV-30694r6_rule
Vulnerability ID: V-24957
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |