UCF STIG Viewer Logo

IT Policy rule “Maximum Security Timeout” (Device-Only policy group) must be set as required.


Overview

Finding ID Version Rule ID IA Controls Severity
V-11876 WIR1450-01 SV-12376r4_rule ECSC-1 Medium
Description
Handheld may not lock after the specified period of inactivity and DoD data could be exposed.
STIG Date
BlackBerry Enterprise Server (version 5.x), Part 3 Security Technical Implementation Guide 2015-07-02

Details

Check Text ( C-14990r4_chk )
Detailed Policy Requirements:

Handheld must be set to lock after 15 minutes or less of inactivity.

*****For this check, set IT Policy rule "Maximum Security Timeout" (Device-Only policy group) to "15 or less".

Check Procedures:

This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545).

*****Verify IT Policy rule "Maximum Security Timeout" (Device-Only policy group) is set as required.

If not set as required, this is a finding.
Fix Text (F-23386r4_fix)
Configure the IT Policy rule as specified in the "Checks" block.