Check: WIR-SPP-008-01
Smartphone Policy:
WIR-SPP-008-01
(in version v1 r8)
Title
The mobile device SA must perform a wipe command on all new or reissued smartphones and a STIG or ISCG-compliant IT policy will be pushed to the device before issuing it to DoD personnel. (Cat III impact)
Discussion
Malware can be installed on the device at some point between shipping from the factory and delivery to DoD. The malware could result in the compromise of sensitive DoD information or result in the introduction of malware within the DoD network.
Check Content
Detailed Policy Requirements: The smartphone system administrator must perform a wipe command on all new or reissued smartphones and reload system software and load a STIG or ISCG-compliant security policy on the smartphone before issuing it to DoD personnel and placing the device on a DoD network. When wireless activation is performed, the activation password is passed to the user in a secure manner (e.g., activation password is encrypted and emailed to an individual). Check Procedures: Interview the IAO. Verify required procedures are followed. Mark as a finding if required procedures were not followed.
Fix Text
The mobile device system administrator must perform a wipe command on all new or reissued mobile devices.
Additional Identifiers
Rule ID: SV-30700r3_rule
Vulnerability ID: V-24963
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |