UCF STIG Viewer Logo

BlackBerry Enterprise Mobility Server 3.x Security Technical Implementation Guide


Overview

Date Finding Count (27)
2023-05-17 CAT I (High): 2 CAT II (Med): 24 CAT III (Low): 1
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC III - Administrative Sensitive)

Finding ID Severity Title
V-254716 High The BlackBerry Enterprise Mobility Server (BEMS) must be configured to use HTTPS.
V-254727 High If the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use SSL for LDAP lookup to connect to the Office Web App Server (e.g., SharePoint).
V-254710 Medium The firewall protecting the BEMS must be configured to restrict all network traffic to and from all addresses with the exception of ports, protocols, and IP address ranges required to support BEMS functions.
V-254711 Medium The firewall protecting the BlackBerry Enterprise Mobility Server (BEMS) must be configured so that only DOD-approved ports, protocols, and services are enabled.
V-254712 Medium The BlackBerry Enterprise Mobility Server (BEMS) must protect the confidentiality and integrity of transmitted information through the use of an approved TLS version.
V-254713 Medium The BlackBerry Enterprise Mobility Server (BEMS) must remove all export ciphers to protect the confidentiality and integrity of transmitted information.
V-254714 Medium The BlackBerry Enterprise Mobility Server (BEMS) must be configured to have at least one user in the following Administrator roles: Server primary administrator, auditor.
V-254715 Medium The BlackBerry Enterprise Mobility Server (BEMS) must be configured to use Windows Authentication for the database connection.
V-254717 Medium The BlackBerry Enterprise Mobility Server (BEMS) must be configured to use DOD certificates for SSL.
V-254718 Medium The BlackBerry Enterprise Mobility Server (BEMS) must be configured with an inactivity timeout of 15 minutes or less.
V-254719 Medium If the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.
V-254732 Medium If the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable the proxy server authentication type (if a proxy is used).
V-254730 Medium If the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable the Web Proxy.
V-254729 Medium The BlackBerry Enterprise Mobility Server (BEMS) server must be configured to enable FIPS mode.
V-254728 Medium If the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable audit logs.
V-254721 Medium If the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to Enable SSL LDAP when using LDAP Lookup for users.
V-254720 Medium If the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Integrated Authentication for the Exchange connection.
V-254723 Medium If the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.
V-254722 Medium If the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to Enable SSL LDAP for certificate directory lookup.
V-254725 Medium If the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.
V-254724 Medium If the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable SSL support for BlackBerry Proxy and use only DOD approved certificates.
V-254726 Medium If the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use NTLM authentication.
V-254707 Medium The BlackBerry Enterprise Mobility Server (BEMS) must protect log information from unauthorized modification.
V-254706 Medium The BlackBerry Enterprise Mobility Server (BEMS) must protect log information from any type of unauthorized read access.
V-254709 Medium The BlackBerry Enterprise Mobility Server (BEMS) platform must be protected by a DOD-approved firewall.
V-254708 Medium The BlackBerry Enterprise Mobility Server (BEMS) must protect log information from unauthorized deletion.
V-254731 Low If the BlackBerry Presence service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured with the whitelisting control to limit presence subscriptions to only single domain/tenant.