UCF STIG Viewer Logo

The Good Mobility Suite server must disable copying data from inside a security container to a non-secure data area on a mobile device via centrally managed policy.


Overview

Finding ID Version Rule ID IA Controls Severity
V-53049 GOOD-00-000540 SV-67265r1_rule Medium
Description
Security-related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not implemented, the system may be vulnerable to a variety of attacks. The use of a Good Mobility Suite allows an organization to assign values to security-related parameters across all the devices it manages. This provides assurance that the required mobile OS security controls are being enforced and that the device user or an adversary has not modified or disabled the controls. It also greatly increases efficiency and manageability of devices in a large-scale environment relative to an environment in which each device must be configured separately. If this control is not available, sensitive DoD data stored inside the security container could be exposed if it is copied to a non-secure area on the device.
STIG Date
Good for Enterprise 8.x Security Technical Implementation Guide 2014-08-18

Details

Check Text ( C-54553r1_chk )
Review the Good Mobility Suite server configuration to determine whether the capability to disable the copying of data stored inside the security container to an unsecured area outside the container has been disabled. Otherwise, this is a finding.
Fix Text (F-57859r2_fix)
Configure the centrally managed Good Mobility Suite security policy rule to disable the copying of data stored inside the security container to an unsecured area outside the container.

-Launch the Good Mobile Control Web console and click on the Policies tab
-Select the policy set for the smart phone and select the Messaging tab
-Verify Do not allow data to be copied from the Good application is unchecked
-Select the File Handling tab and make sure Enable importing to Good only is selected
-Verify Exceptions to importing/exporting between Good and 3rd party is checked and Trust only these external applications is selected