UCF STIG Viewer Logo

Mobile Application Management (MAM) Server Security Technical Implementation Guide (STIG)


Overview

Date Finding Count (14)
2012-07-20 CAT I (High): 4 CAT II (Med): 7 CAT III (Low): 3
STIG Description
This STIG provides technical security controls required for the use of a MAM server to manage applications installed on mobile devices in the DoD environment. The requirements listed in this benchmark apply to any DoD iOS 5 implementation when iOS 5 devices process sensitive DoD information, connect to a DoD network or network connected PC, or provide service to a DoD email system. The requirements can be implemented in an application server separate from the MDM server or included in the MDM server.

Available Profiles



Findings (MAC I - Mission Critical Sensitive)

Finding ID Severity Title
V-24975 High The host server where the mobile management server is installed must have a host-based or appliance firewall, which must be configured as required.
V-26564 High Authentication on system administration accounts for mobile management servers must be configured to support Microsoft Active Directory (AD) authentication.
V-32769 High The MAM server must manage a list of required applications (white list) by device account and by group account.
V-32771 High The MAM server must scan the list of installed applications on managed mobile devices on a predefined periodic basis and take a predefined action if unapproved applications are found.
V-24973 Medium The host server where the mobile management server is installed must be hardened according to the appropriate Application STIG (SQL, Apache Web Server, Apache Tomcat, IIS, etc.).
V-32767 Medium The MAM server must be able to obtain applications from a DoD managed application store.
V-32770 Medium The MAM server must prohibit the removal of required applications on managed devices or alert and take a predefined action if required applications have been removed.
V-32773 Medium The MAM server must prevent unauthorized and unintended access to shared system resources by applications on managed mobile devices.
V-32772 Medium The MAM server must manage the installation of updates and patches for installed applications on managed mobile devices.
V-32775 Medium The MAM server must install DoD managed applications, including the browser, email client, and VPN client, in an approved security container on managed mobile devices.
V-32774 Medium The MAM server must enable the inspection of installed applications on a managed iOS device.
V-25754 Low The PKI digital certificate installed on mobile management servers must be a DoD PKI-issued certificate.
V-32768 Low The MAM server must install required applications on managed mobile devices.
V-33231 Low The master AES encryption key used to encrypt data between the management server and the agent on the mobile device must be changed on a periodic basis.