UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The mobile device used for BYOAD must be NIAP validated.


Overview

Finding ID Version Rule ID IA Controls Severity
V-259759 AIOS-17-800280 SV-259759r943602_rule High
Description
Note: For a virtual mobile infrastructure (VMI) solution, both the client and server components must be NIAP compliant. Nonapproved mobile devices may not include sufficient controls to protect work data, applications, and networks from malware or adversary attack. Components must only approve devices listed on the NIAP product compliant list or products listed in evaluation at the following links respectively: - https://www.niap-ccevs.org/Product/ - https://www.niap-ccevs.org/Product/PINE.cfm Reference: DOD policy "Use of Non-Government Mobile Devices". 3.b.(1)i. SFR ID: FMT_SMF_EXT.1.1 #47
STIG Date
Apple iOS/iPadOS 17 BYOAD Security Technical Implementation Guide 2024-01-31

Details

Check Text ( C-63495r943600_chk )
Verify the mobile device used for BYOAD is NIAP validated (included on the NIAP list of compliant products or products in evaluation).

If the mobile device used for BYOAD is not NIAP validated (included on the NIAP list of compliant products or products in evaluation), this is a finding.
Fix Text (F-63402r943601_fix)
Use only mobile devices for BYOAD that are NIAP validated (included on the NIAP list of compliant products or products in evaluation).