UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Mobile Application Management (MAM) Server Security Technical Implementation Guide (STIG)


Overview

Date Finding Count (14)
2012-07-20 CAT I (High): 4 CAT II (Med): 7 CAT III (Low): 3
STIG Description
This STIG provides technical security controls required for the use of a MAM server to manage applications installed on mobile devices in the DoD environment. The requirements listed in this benchmark apply to any DoD iOS 5 implementation when iOS 5 devices process sensitive DoD information, connect to a DoD network or network connected PC, or provide service to a DoD email system. The requirements can be implemented in an application server separate from the MDM server or included in the MDM server.

Available Profiles



Findings (MAC III - Administrative Classified)

Finding ID Severity Title
V-24975 High The host server where the mobile management server is installed must have a host-based or appliance firewall, which must be configured as required.
V-26564 High Authentication on system administration accounts for mobile management servers must be configured to support Microsoft Active Directory (AD) authentication.
V-32769 High The MAM server must manage a list of required applications (white list) by device account and by group account.
V-32771 High The MAM server must scan the list of installed applications on managed mobile devices on a predefined periodic basis and take a predefined action if unapproved applications are found.
V-24973 Medium The host server where the mobile management server is installed must be hardened according to the appropriate Application STIG (SQL, Apache Web Server, Apache Tomcat, IIS, etc.).
V-32767 Medium The MAM server must be able to obtain applications from a DoD managed application store.
V-32770 Medium The MAM server must prohibit the removal of required applications on managed devices or alert and take a predefined action if required applications have been removed.
V-32773 Medium The MAM server must prevent unauthorized and unintended access to shared system resources by applications on managed mobile devices.
V-32772 Medium The MAM server must manage the installation of updates and patches for installed applications on managed mobile devices.
V-32775 Medium The MAM server must install DoD managed applications, including the browser, email client, and VPN client, in an approved security container on managed mobile devices.
V-32774 Medium The MAM server must enable the inspection of installed applications on a managed iOS device.
V-25754 Low The PKI digital certificate installed on mobile management servers must be a DoD PKI-issued certificate.
V-32768 Low The MAM server must install required applications on managed mobile devices.
V-33231 Low The master AES encryption key used to encrypt data between the management server and the agent on the mobile device must be changed on a periodic basis.