BB10-00-000310 | High | Only DoD PKI issued or DoD approved software authentication certificates may be installed on the work space of the BlackBerry 10 OS. | If unauthorized software authentication certificates are installed on the device, then the operating system would not block malware signed by the entity that published these certificates. Such... |
BB10-00-000220 | High | BlackBerry 10 OS must prevent a user from installing unapproved applications. | The operating system must enforce software installation by users based upon what types of software installations are permitted (e.g., updates and security patches to existing software) and what... |
BB10-00-000360 | Medium | BlackBerry 10 OS must employ mobile device management services to centrally manage IT Policies. | Security related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not... |
BB10-00-000240 | Medium | BlackBerry 10 OS's Wi-Fi module must use EAP-TLS authentication when authenticating to DoD WLAN authentication servers. | Without strong mutual authentication, a mobile device may connect to an unauthorized network. In many cases, the user may falsely believe that the device is connected to an authorized network and... |
BB10-00-000320 | Medium | Only DoD PKI issued or DoD approved server authentication certificates may be installed on the work space of the BlackBerry 10 OS. | If unauthorized device authentication certificates are installed on the device, there is the potential that the device may connect to a rogue device or network. Rogue devices can mimic the... |
BB10-00-000410 | Medium | BlackBerry 10 OS must prohibit wireless remote access connections for storage. | The device acts as a personal hotspot when it accepts remote connections on a local area network interface for the purposes of routing traffic to a wide area network interface. The most common... |
BB10-00-000290 | Medium | BlackBerry 10 OS must prohibit the use of non-DoD authorized instant messaging (IM) systems. | Many instant messaging systems have known vulnerabilities, some of which allow an adversary to install malware on the device. This malware can then be used to obtain sensitive information or... |
BB10-00-000390 | Medium | BlackBerry 10 OS must employ mobile device management services to centrally manage VPN profiles. | Security related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not... |
BB10-00-000120 | Medium | BlackBerry 10 OS must retain the device lock until the user reestablishes access using established identification and authentication procedures. | The device lock function prevents further access to the system by initiating a session lock after a period of inactivity or upon receiving a request from a user. The device lock is retained until... |
BB10-00-000230 | Medium | BlackBerry 10 OS must only permit download of software from a DoD approved source (e.g., DoD operated mobile device application store or MDM server). | DoD can perform due diligence on sources of software to mitigate the risk that malicious software is introduced to those sources. Therefore, if software is downloaded from a DoD approved source,... |
BB10-00-000160 | Medium | BlackBerry 10 OS must disallow the device unlock password from containing fewer than a specified minimum numbers of upper case alphabetic characters. | Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute force attack. Setting minimum numbers of certain types of characters increases... |
BB10-00-000370 | Medium | BlackBerry 10 OS must employ mobile device management services to centrally manage email settings. | Security related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not... |
BB10-00-000210 | Medium | BlackBerry 10 OS must enforce a minimum length for the work area password. | Password complexity, or strength, is a measure of the effectiveness of a password in resisting guessing and brute force attacks. The ability to crack a password is a function of how many attempts... |
BB10-00-000140 | Medium | BlackBerry 10 OS must prevent applications from extending the password lock time. | The device lock function prevents further access to the system by initiating a session lock after a period of inactivity or upon receiving a request from a user. The device lock is retained until... |
BB10-00-000270 | Medium | BlackBerry 10 OS's VPN client must use either IPSec or SSL/TLS when connecting to DoD networks. | Use of non-standard communications protocols can affect both the availability and confidentiality of communications. IPSec and SSL/TLS are both well-known and tested protocols that provide strong... |
BB10-00-000330 | Medium | BlackBerry 10 OS must prevent a user from using a browser that does not direct its traffic to a DoD proxy server. | Proxy servers can inspect traffic for malware and other signs of a security attack. Allowing a mobile device to access the public Internet without proxy server inspection forgoes the protection... |
BB10-00-000250 | Medium | BlackBerry 10 OS VPN client must employ DoD approved PKI mechanisms for authentication when connecting to DoD networks. | VPNs are vulnerable to attack if they are not supported by strong authentication. An adversary may be able to gain access to network resources and sensitive information if they can compromise the... |
BB10-00-000180 | Medium | BlackBerry 10 OS must disallow the device unlock password from containing fewer than a specified minimum number of numeric characters. | Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute force attack. Setting minimum numbers of certain types of characters increases... |
BB10-00-000400 | Medium | BlackBerry 10 OS must re-encrypt all device data when the device is locked. | If data is not encrypted upon the lock of the device, there is the potential for an adversary to remove non-volatile memory from the device and read it directly using tools for that purpose. This... |
BB10-00-000420 | Medium | BlackBerry 10 OS must prohibit wireless remote access connections for media sharing | The device acts as a personal hotspot when it accepts remote connections on a local area network interface for the purposes of routing traffic to a wide area network interface. The most common... |
BB10-00-000380 | Medium | BlackBerry 10 OS must employ mobile device management services to centrally manage Wi-Fi profiles. | Security related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not... |
BB10-00-000130 | Medium | BlackBerry 10 OS must lock the device after no more than 15 minutes of inactivity. | The device lock function prevents further access to the system by initiating a session lock after a period of inactivity or upon receiving a request from a user. The device lock is retained until... |
BB10-00-000110 | Medium | BlackBerry 10 OS must retain the device lock until the user reestablishes access using established identification and authentication procedures. | The device lock function prevents further access to the system by initiating a session lock after a period of inactivity or upon receiving a request from a user. The device lock is retained until... |
BB10-00-000340 | Medium | BlackBerry 10 OS must prevent a user from using a browser that does not direct its traffic to a DoD proxy server. | Proxy servers can inspect traffic for malware and other signs of a security attack. Allowing a mobile device to access the public Internet without proxy server inspection forgoes the protection... |
BB10-00-000170 | Medium | BlackBerry 10 OS must disallow the device unlock password from containing fewer than a specified minimum number of lower case alphabetic characters. | Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute force attack. Setting minimum numbers of certain types of characters increases... |
BB10-00-000200 | Low | BlackBerry 10 OS must prohibit a user from reusing any of the last five previously used device unlock passwords. | Password complexity, or strength, is a measure of the effectiveness of a password in resisting guessing and brute force attacks. Remembering the prior five device unlock passwords enables the... |
BB10-00-000150 | Low | BlackBerry 10 OS must synchronize the internal clock at least once every 24 hours with an authoritative time server or the Global Positioning System. | Determining the correct time a particular application event occurred on a system is critical when conducting forensic analysis and investigating system events.
Periodically synchronizing... |
BB10-00-000260 | Low | BlackBerry 10 OS must cryptographically bind the removable media to the mobile device so data stored on the removable media can only be read by that mobile device. | When data is written to portable digital media, such as thumb drives, floppy diskettes, compact disks, and magnetic tape, etc., there is risk of data loss. Cryptographically binding the removable... |
BB10-00-000190 | Low | BlackBerry 10 OS must enforce a maximum lifetime of 120 days for the device unlock password (password age). | Changing passcodes regularly prevents an attacker who has compromised the password from re-using it to regain access. This is an unlikely scenario, but is addressed by setting a password... |
BB10-00-000430 | Low | BlackBerry 10 OS must enable a system administrator to select which data fields will be available to applications outside of the contact database application. | The contact database often contains a significant amount of information beyond each person's name and phone number. The records may contain addresses and other identifying or sensitive information... |
BB10-00-000100 | Low | BlackBerry 10 OS must display the DoD warning banner exactly as specified at startup device unlock. | The operating system is required to display the DoD approved system use notification message or banner before granting access to the system that provides privacy and security notices consistent... |