Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-18619 | WIR0405 | SV-20177r1_rule | ECCT-1 | Medium |
Description |
---|
Sensitive unclassified voice and data communications could be intercepted and exposed if required security controls are not used. |
STIG | Date |
---|---|
Bluetooth/Zigbee Security Technical Implementation Guide (STIG) | 2014-03-18 |
Check Text ( C-22301r1_chk ) |
---|
Ask the IAO for documentation verifying Bluetooth peripherals (e.g., headsets) used by personnel at the site conform to the DoD Bluetooth Peripheral Device Security Requirements Specification (i.e., verification from NSA, DISA, or a DoD test agency). The specification is found at http://iase.disa.mil/stigs/net_perimeter/wireless/smartphone.html and http://www.nsa.gov/ia/_files/wireless/BlueToothDoc.pdf. |
Fix Text (F-34125r1_fix) |
---|
Procure Bluetooth headsets that conform to the DoD Bluetooth Peripheral Device Security Requirements Specification. |