UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

BlackBerry 10 OS Security Technical Implementation Guide


Overview

Date Finding Count (36)
2014-08-27 CAT I (High): 4 CAT II (Med): 28 CAT III (Low): 4
STIG Description
Developed by BlackBerry Ltd. in coordination with DISA for use in the DoD. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.letterkenny.FSO.mbx.stig-customer-support-mailbox@mail.mil.

Available Profiles



Findings (MAC III - Administrative Sensitive)

Finding ID Severity Title
V-53889 High BlackBerry 10 OS versions no longer supported by the manufacturer or vendor must not be installed on a device.
V-40714 High BlackBerry 10 OS must grant a downloaded application only the permissions that DoD has authorized for that application.
V-38311 High Only DoD PKI issued or DoD approved software authentication certificates may be installed on the Work Space of the BlackBerry 10 OS.
V-38302 High BlackBerry 10 OS must prevent a user from installing unapproved applications.
V-39313 Medium BlackBerry 10 OS must be updated to the latest approved version of the operating system.
V-39316 Medium BlackBerry 10 OS must support both software-based and hardware-based asymmetric key technology (e.g., CAC/PIV).
V-39315 Medium BlackBerry 10 OS must enforce complexity requirements for the authentication to access private keys saved in the key certificate stores.
V-38309 Medium BlackBerry 10 OS must prohibit the use of non-DoD authorized instant messaging (IM) systems.
V-38319 Medium BlackBerry 10 OS must employ mobile device management services to centrally manage VPN profiles.
V-38318 Medium BlackBerry 10 OS must employ mobile device management services to centrally manage Wi-Fi profiles.
V-40716 Medium BlackBerry 10 OS maximum number of consecutive unsuccessful unlock attempts must be configurable within a range from 5 to 10.
V-40717 Medium BlackBerry 10 OS must use a DoD proxy server.
V-38316 Medium BlackBerry 10 OS must employ mobile device management services to centrally manage IT Policies.
V-40713 Medium BlackBerry 10 OS must have access to DoD root and intermediate PKI certificates when performing DoD PKI related transactions.
V-38313 Medium BlackBerry 10 OS must prevent a user from using a browser that does not direct its Wi-Fi traffic to a DoD proxy server.
V-38312 Medium Only DoD PKI issued or DoD approved server authentication certificates may be installed on the Work Space of the BlackBerry 10 OS.
V-38298 Medium BlackBerry 10 OS must disallow the Work Space unlock password from containing fewer than a specified minimum number of numeric characters.
V-38314 Medium BlackBerry 10 OS must prevent a user from using a browser that does not direct its VPN traffic to a DoD proxy server.
V-38291 Medium BlackBerry 10 OS must retain the work space lock until the user reestablishes access using established identification and authentication procedures.
V-38292 Medium BlackBerry 10 OS must retain the device lock until the user reestablishes access using established identification and authentication procedures.
V-38293 Medium BlackBerry 10 OS must lock the Work Space after no more than 15 minutes of inactivity.
V-38294 Medium BlackBerry 10 OS must prevent applications from extending the Work Space password lock time.
V-38317 Medium BlackBerry 10 OS must employ mobile device management services to centrally manage email settings.
V-38296 Medium BlackBerry 10 OS must disallow the Work Space unlock password from containing fewer than a specified minimum number of upper case alphabetic characters.
V-38297 Medium BlackBerry 10 OS must disallow the Work Space unlock password from containing fewer than a specified minimum number of lower case alphabetic characters.
V-38321 Medium BlackBerry 10 OS must prohibit wireless remote access connections for storage.
V-38322 Medium BlackBerry 10 OS must prohibit wireless remote access connections for media sharing
V-38303 Medium BlackBerry 10 OS must only permit download of software from a DoD approved source (e.g., DoD operated mobile device application store or MDM server).
V-38301 Medium BlackBerry 10 OS must enforce a minimum length for the Work Space unlock password.
V-38307 Medium BlackBerry 10 OSs VPN client must use either IPSec or SSL/TLS when connecting to DoD networks.
V-38304 Medium BlackBerry 10 OSs Wi-Fi module must use EAP-TLS authentication when authenticating to DoD WLAN authentication servers.
V-38305 Medium BlackBerry 10 OS VPN client must employ DoD approved PKI mechanisms for authentication when connecting to DoD networks.
V-38295 Low BlackBerry 10 OS must synchronize the internal clock at least once every 24 hours with an authoritative time server or the Global Positioning System.
V-39314 Low BlackBerry 10 OS must prevent DoD applications from accessing non-DoD data when the device supports multiple user environments (e.g., work and personal) if such access has not been approved.
V-38290 Low BlackBerry 10 OS must display the DoD warning banner exactly as specified at startup device unlock.
V-38323 Low BlackBerry 10 OS must enable a system administrator to select which data fields will be available to applications outside of the contact database application.