UCF STIG Viewer Logo

Mobile operating system (OS) based CMDs and systems must not be used to send, receive, store, or process classified messages unless specifically approved by NSA for such purposes and NSA approved transmission and storage methods are used.


Overview

Finding ID Version Rule ID IA Controls Severity
V-24960 WIR-SPP-005 SV-30697r3_rule ECWN-1 High
Description
DoDD 8100.2 states wireless devices will not be used for classified data unless approved for such use. Classified data could be exposed to unauthorized personnel.
STIG Date
General Mobile Device Policy (Non-Enterprise Activated) Security Technical Implementation Guide 2013-07-03

Details

Check Text ( C-31119r4_chk )
Interview the IAO.

Verify written policy and training material exists (or requirement is listed on a signed user agreement) stating CMDs must not be used to transmit classified information unless approved for use.

Mark as a finding if written policy or training material does not exist, stating CMDs must not be used to receive, transmit, or process classified information.
Fix Text (F-27587r4_fix)
Publish written policy or training material stating CMDs must not process, send, or receive classified information unless approved for use.