UCF STIG Viewer Logo

BlackBerry PlayBook OS must retain the device lock until the user reestablishes access using established identification and authentication procedures.


Overview

Finding ID Version Rule ID IA Controls Severity
V-38704 PB21-00-000110 SV-50509r1_rule Medium
Description
The device lock function prevents further access to the system by initiating a session lock after a period of inactivity or upon receiving a request from a user. The device lock is retained until the user reestablishes access using established identification and authentication procedures. A device lock is a temporary action taken when a user stops work but does not want to log out because of the temporary nature of the hiatus. During the device lock a publicly viewable pattern is visible on the associated display, hiding what was previously visible on the screen. Once invoked, the device lock shall remain in place until the user re-authenticates. No other system activity aside from re-authentication can unlock the system. The operating system must enforce a device lock function. This prevents others from gaining access to the device when not in the user's possession and accessing sensitive DoD information. The identification and authentication procedure configuration must be set by a Mobile Device Management (MDM) service and be sufficiently complex to protect sensitive data.
STIG Date
BlackBerry PlayBook OS V2.1 Security Technical Implementation Guide 2014-08-29

Details

Check Text ( C-46272r1_chk )
Navigate to "Options -> Security ->Password" and ensure "Enable Password" is set to "ON". Otherwise, this is a finding.
Fix Text (F-43658r1_fix)
Navigate to "Options -> Security ->Password" and set "Enable Password" is set to "ON". Create a 4 digit passcode for the device lock.