UCF STIG Viewer Logo

BlackBerry devices must be protected by authenticated login procedures to unlock the device. Either CAC or Password authentication is required. IT Policy rule Password Pattern Checks (Device Only policy group) must be set as required.


Overview

Finding ID Version Rule ID IA Controls Severity
V-37372 WIR1400-12 SV-49134r1_rule ECSC-1 IAIA-1 Medium
Description
Authenticated device unlock is a key security control for the BlackBerry system to restrict access to DoD data by unauthorized individuals. If the password complexity is not compliant, it may be possible for a hacker to guess the password.
STIG Date
BlackBerry Enterprise Server (version 5.x), Part 3 Security Technical Implementation Guide 2013-09-30

Details

Check Text ( C-45620r1_chk )
Detailed Policy Requirements:

See Check WIR1400-01 (V0003545 ) for detailed policy requirements.

*****For this check, Set IT Policy rule “Password Pattern Checks” (Device Only policy group) to “At least 1 upper-case alpha, 1 lower-case alpha, 1 numeric, and 1 special character”.
Check Procedures:

This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545).

Interview the IAO and administrator.

*****Verify IT Policy rule “Password Pattern Checks” (Device Only policy group) is set as required.
Fix Text (F-42297r1_fix)
Configure the IT Policy rule Password Pattern Checks as specified in the "Checks" block.