UCF STIG Viewer Logo

BlackBerry 10 OS Security Technical Implementation Guide


Overview

Date Finding Count (36)
2014-08-27 CAT I (High): 4 CAT II (Med): 28 CAT III (Low): 4
STIG Description
Developed by BlackBerry Ltd. in coordination with DISA for use in the DoD. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.letterkenny.FSO.mbx.stig-customer-support-mailbox@mail.mil.

Available Profiles



Findings (MAC I - Mission Critical Classified)

Finding ID Severity Title
V-53889 High BlackBerry 10 OS versions no longer supported by the manufacturer or vendor must not be installed on a device.
V-40714 High BlackBerry 10 OS must grant a downloaded application only the permissions that DoD has authorized for that application.
V-38311 High Only DoD PKI issued or DoD approved software authentication certificates may be installed on the Work Space of the BlackBerry 10 OS.
V-38302 High BlackBerry 10 OS must prevent a user from installing unapproved applications.
V-39313 Medium BlackBerry 10 OS must be updated to the latest approved version of the operating system.
V-39316 Medium BlackBerry 10 OS must support both software-based and hardware-based asymmetric key technology (e.g., CAC/PIV).
V-39315 Medium BlackBerry 10 OS must enforce complexity requirements for the authentication to access private keys saved in the key certificate stores.
V-38309 Medium BlackBerry 10 OS must prohibit the use of non-DoD authorized instant messaging (IM) systems.
V-38319 Medium BlackBerry 10 OS must employ mobile device management services to centrally manage VPN profiles.
V-38318 Medium BlackBerry 10 OS must employ mobile device management services to centrally manage Wi-Fi profiles.
V-40716 Medium BlackBerry 10 OS maximum number of consecutive unsuccessful unlock attempts must be configurable within a range from 5 to 10.
V-40717 Medium BlackBerry 10 OS must use a DoD proxy server.
V-38316 Medium BlackBerry 10 OS must employ mobile device management services to centrally manage IT Policies.
V-40713 Medium BlackBerry 10 OS must have access to DoD root and intermediate PKI certificates when performing DoD PKI related transactions.
V-38313 Medium BlackBerry 10 OS must prevent a user from using a browser that does not direct its Wi-Fi traffic to a DoD proxy server.
V-38312 Medium Only DoD PKI issued or DoD approved server authentication certificates may be installed on the Work Space of the BlackBerry 10 OS.
V-38298 Medium BlackBerry 10 OS must disallow the Work Space unlock password from containing fewer than a specified minimum number of numeric characters.
V-38314 Medium BlackBerry 10 OS must prevent a user from using a browser that does not direct its VPN traffic to a DoD proxy server.
V-38291 Medium BlackBerry 10 OS must retain the work space lock until the user reestablishes access using established identification and authentication procedures.
V-38292 Medium BlackBerry 10 OS must retain the device lock until the user reestablishes access using established identification and authentication procedures.
V-38293 Medium BlackBerry 10 OS must lock the Work Space after no more than 15 minutes of inactivity.
V-38294 Medium BlackBerry 10 OS must prevent applications from extending the Work Space password lock time.
V-38317 Medium BlackBerry 10 OS must employ mobile device management services to centrally manage email settings.
V-38296 Medium BlackBerry 10 OS must disallow the Work Space unlock password from containing fewer than a specified minimum number of upper case alphabetic characters.
V-38297 Medium BlackBerry 10 OS must disallow the Work Space unlock password from containing fewer than a specified minimum number of lower case alphabetic characters.
V-38321 Medium BlackBerry 10 OS must prohibit wireless remote access connections for storage.
V-38322 Medium BlackBerry 10 OS must prohibit wireless remote access connections for media sharing
V-38303 Medium BlackBerry 10 OS must only permit download of software from a DoD approved source (e.g., DoD operated mobile device application store or MDM server).
V-38301 Medium BlackBerry 10 OS must enforce a minimum length for the Work Space unlock password.
V-38307 Medium BlackBerry 10 OSs VPN client must use either IPSec or SSL/TLS when connecting to DoD networks.
V-38304 Medium BlackBerry 10 OSs Wi-Fi module must use EAP-TLS authentication when authenticating to DoD WLAN authentication servers.
V-38305 Medium BlackBerry 10 OS VPN client must employ DoD approved PKI mechanisms for authentication when connecting to DoD networks.
V-38295 Low BlackBerry 10 OS must synchronize the internal clock at least once every 24 hours with an authoritative time server or the Global Positioning System.
V-39314 Low BlackBerry 10 OS must prevent DoD applications from accessing non-DoD data when the device supports multiple user environments (e.g., work and personal) if such access has not been approved.
V-38290 Low BlackBerry 10 OS must display the DoD warning banner exactly as specified at startup device unlock.
V-38323 Low BlackBerry 10 OS must enable a system administrator to select which data fields will be available to applications outside of the contact database application.