UCF STIG Viewer Logo

The Good Mobility Suite server must perform required actions when a security-related alert is received.


Overview

Finding ID Version Rule ID IA Controls Severity
V-53029 GOOD-00-000640 SV-67245r1_rule High
Description
Incident response functions are intended to monitor, detect, and alarm on defined events occurring on the system or on the network. A large part of their functionality is accurate and timely notification of events. Notifications can be made more efficient by the creation of notification groups containing members who would be responding to a particular alarm or event. Types of actions the Good Mobility Suite must be able to perform after a security alert include: log the alert, send email to a system administrator, wipe the managed mobile device, lock the mobile device account on the Good Mobility Suite, disable the security container, wipe the security container, and delete an unapproved application. Security alerts include any alert from the MDIS or MAM component of the Good Mobility Suite.
STIG Date
Good for Enterprise 8.x Security Technical Implementation Guide 2014-08-18

Details

Check Text ( C-54529r1_chk )
Review the Good Mobility Suite configuration to determine if it has the capability to perform required actions after receiving a security-related alert. Otherwise, this is a finding.
Fix Text (F-57839r2_fix)
Use a Good Mobility Suite that can perform required actions after receiving security related alerts.

-Launch the Good Mobile Control Web console and click on the Policies tab
-Select a policy set to review and click on the policy
-On the left tab, select Compliance Manager under Mobile Device Management and click Add Rule
- Select the Compliance Rule
- Under Failure Action, select the appropriate action