UCF STIG Viewer Logo

The MDM server must retain the logon banner on the screen unless the administrator takes explicit actions to logon to the server.


Overview

Finding ID Version Rule ID IA Controls Severity
V-36012 SRG-APP-069-MDM-007-SRV SV-47401r1_rule Low
Description
To establish acceptance of system usage policy, a click-through banner at application logon is required. The banner shall prevent further activity on the application unless and until the user executes a positive action to manifest agreement by clicking on a box indicating "OK". The text of this banner should be customizable in the event of future user agreement changes. Failure to display the required login warning banner prior to log on attempts will limit the ability to prosecute unauthorized access and also presents the potential to give rise to criminal and civil liability for systems administrators and information systems managers. In addition, DoD's ability to monitor the device's usage is limited unless a proper warning banner is displayed.
STIG Date
Mobile Device Manager Security Requirements Guide 2013-01-24

Details

Check Text ( C-44251r1_chk )
Review the MDM server configuration to determine that the logon banner is displayed until the user takes action to acknowledge the agreement. If the banner is presented by the operating system, a banner presented by the MDM server application is not required. If the banner screen continues on to the logon screen without user interaction, this is a finding.
Fix Text (F-40542r1_fix)
Configure the MDM server to retain the logon banner on the screen unless the administrator takes explicit actions to logon to the server.