UCF STIG Viewer Logo

Site BlackBerry devices must be provisioned so users can digitally sign and encrypt e-mail notifications or any other email required by DoD policy. IT Policy rule “S/MIME Allowed Content Ciphers” (S/MIME Application policy group) must be set as required.


Overview

Finding ID Version Rule ID IA Controls Severity
V-19292 WIR1420-11 SV-21208r4_rule ECSC-1 Low
Description
S/MIME provides the capability for users to send and receive S/MIME email messages from wireless email devices. S/MIME and digital signatures provide assurance the message is authentic and is required by DoD policy.
STIG Date
BlackBerry Enterprise Server (version 5.x), Part 3 Security Technical Implementation Guide 2015-07-02

Details

Check Text ( C-23339r4_chk )
Detailed Policy Requirements:

***** For this check, set IT Policy rule "S/MIME Allowed Content Ciphers" (S/MIME Application policy group) to "Check the following:

0 (AES-256 bit)
1 (AES-192 bit)
2 (AES-128 bit)
5 (Triple DES)"

Check Procedures:

This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545).

*****Verify IT Policy rule "S/MIME Allowed Content Ciphers" (S/MIME Application policy group) is set as required.

If not set as required, this is a finding.
Fix Text (F-23386r4_fix)
Configure the IT Policy rule as specified in the "Checks" block.