Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-19724 | WIR1450-09 | SV-21865r2_rule | ECSC-1 | Medium |
Description |
---|
BlackBerry could be at risk if an application is able to open an internal and external connection on the BlackBerry at the same time. The BlackBerry could be exposed to Malware. |
STIG | Date |
---|---|
BlackBerry Enterprise Server (version 5.x), Part 3 Security Technical Implementation Guide | 2013-06-21 |
Check Text ( C-24161r2_chk ) |
---|
Detailed Policy Requirements: Split-pipe connections are not allowed on DoD BlackBerrys. *****For this check, set IT Policy rule “Allow Split-Pipe connections” (Security policy group) to “No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Allow Split-Pipe connections” (Security policy group) is set as required. |
Fix Text (F-23386r2_fix) |
---|
Configure the IT Policy rule Require FIPS Ciphers as specified in the "Checks" block. |