UCF STIG Viewer Logo

BlackBerry PlayBook OS must authenticate devices before establishing remote network (e.g., VPN) connections using bidirectional cryptographically based authentication between devices.


Overview

Finding ID Version Rule ID IA Controls Severity
V-38742 PB21-00-000250 SV-50547r1_rule Medium
Description
Without strong mutual authentication a mobile device may connect to an unauthorized network. In many cases, the user may falsely believe that the device is connected to an authorized network and then provide authentication credentials and other sensitive information. A strong bidirectional cryptographically based authentication method mitigates this risk.
STIG Date
BlackBerry PlayBook OS V2.1 Security Technical Implementation Guide 2014-08-29

Details

Check Text ( C-46287r1_chk )
1. Navigate to "Options -> Security -> VPN".
2. Select the enterprise VPN Profile (Work VPN Profiles have a briefcase icon on the right hand side).
3. Verify "Authentication Type" is set to a bidirectional cryptographically based authentication, and greyed out. Otherwise, this is a finding.
Fix Text (F-43697r1_fix)
On BlackBerry Device Service:
Create a VPN Profile with approved "Authentication Type" configured, and associate VPN Profile with IT Policy for the affected device.