Review a sample of site managed devices (3-4), interview the IAO, and review product documentation. Note: iOS does not currently meet this requirement but a third-party application (MDM agent, email client, browser, or VPN client) should be used to meet the requirement.
Verify the site uses a third-party application (MDM agent, email client, browser, or VPN client) that is FIPS 140-2 validated. Review system documentation to identify the FIPS 140-2 certificate for the cryptographic module. Visit the NIST web site to verify the certificate is still valid.
Mark as a finding if the site does not use a third-party application (MDM agent, email client, browser, or VPN client) that is FIPS 140-2 validated. |