Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-25000 | WIR-GMMS-011 | SV-30740r2_rule | ECWN-1 | Medium |
Description |
---|
Sensitive DoD data could be compromised if an MDM security profile is not installed on DoD iOS devices. Other iOS profiles do not have access to all security APIs on the iOS device. If the iOS MDM security profile is removed access to the protected Government data inside the security container will not be allowed. The user must be forced to re-install the MDM security profile before gaining access. The mobile device will report the removal and implementation of the MDM security profile to the MDM management server. |
STIG | Date |
---|---|
Mobile Device Management (MDM) Server Security Technical Implementation Guide (STIG) | 2013-01-17 |
Check Text ( C-31150r8_chk ) |
---|
1. Make a list of all iOS security policies listed on the MDM server that have been assigned to iOS devices and review each policy. 2. Select each security policy iOS devices are assigned to and, in turn, verify the required settings are in the policy. Verify the latest available version of the MDM agent is set in the compliance rule. -Verify “Enable MDM profile” is checked. -Verify all access rights for the MDM profile are enabled. This procedure will vary by MDM product. Here are examples of configuration settings that should be enabled, if available: ---Installation, removal, and inspection of configuration profiles. ---Installation, removal, and inspection of provisioning profiles. ---Inspection of installed applications. ---Query of device information. ---Query of network information. ---Restriction-related queries. ---Security-related queries. Note: If there is a finding, note the name of the policy in the Findings Details section in VMS/Component Provided Tracking Database. Mark as a finding if the MDM profile and required access rights are not set as required. |
Fix Text (F-27643r2_fix) |
---|
Configure the MDM server to enable an MDM security profile and access rights of the profile on each managed iOS device. |