UCF STIG Viewer Logo

The application server must enforce requirements regarding the connection of mobile devices to organizational information systems.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35634 SRG-APP-000227-AS-NA SV-46921r1_rule Medium
Description
Applications designed to manage the connection of mobile devices to information systems must be able to enforce organizational connectivity requirements or work in conjunction with enterprise tools designed to enforce policy requirements. Mobile devices include portable storage media (e.g., USB memory sticks, external hard disk drives) and portable computing and communications devices with information storage capability (e.g., notebook/laptop computers, personal digital assistants, cellular telephones, digital cameras, and audio recording devices). Organizational connectivity requirements may include usage restrictions and implementation guidance related to mobile devices. Scanning devices for malicious code may be required prior to connecting, as well as updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware (e.g., wireless, infrared). Application Servers do not manage mobile devices. They could host the applications that perform mobile management tasks, but do not have mobile management capabilities.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43977r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-40176r1_fix)
This requirement is NA. No fix is required.