Check: WIR-SPP-002
Smartphone Policy:
WIR-SPP-002
(in versions v1 r8 through v1 r5)
Title
The site physical security policy must state digital cameras (still and video) must not be allowed in any SCIF or other areas where classified documents or information is stored, transmitted, or processed. (Cat I impact)
Discussion
PDAs and cell phones with embedded cameras can be used to photograph classified material and can be easily concealed. Classified information could be compromised. Photos may also be taken of the areas that would facilitate a subsequent physical security breach.
Check Content
Note: This requirement also applies to handheld barcode scanners equipped with imagers, unless the manufacturer certifies the raw image is only used for bar code processing and is not available to any other application. Work with the traditional reviewer to interview the Security Manager. Obtain the following information: 1. Review site’s physical security policy. 2. Verify users are informed of this policy by reviewing user agreements, posted signs, or training material. 3. Powering off, removal of batteries, or blocking Infrared (IR) ports is not acceptable for disabling camera functionality, as these methods have not been tested for efficacy. 4. Mark as a finding if a written policy does not prohibit these devices in classified areas. Note: For smartphone systems, the site should consider disabling smartphone cameras via a smartphone security policy.
Fix Text
Update site physical security policy. Train users on policy.
Additional Identifiers
Rule ID: SV-30691r4_rule
Vulnerability ID: V-24954
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |