UCF STIG Viewer Logo

The MDM server must configure the mobile device agent to prohibit the download of applications on mobile operating system devices without system administrator control (i.e., the SA either downloads and installs the application or enables the user to download/install the application).


Overview

Finding ID Version Rule ID IA Controls Severity
V-36146 SRG-APP-135-MDM-146-MAM SV-47550r1_rule Medium
Description
The installation and execution of unauthorized software on an operating system may allow the application to obtain sensitive information or further compromise the system. If the system administrator has control over what applications are downloaded, then the system administrator can check that only known good programs are installed, which significantly mitigates the risk posed by malicious software.
STIG Date
Mobile Device Manager Security Requirements Guide 2013-01-24

Details

Check Text ( C-44386r1_chk )
Review the MDM server configuration to ensure the MDM server can configure the mobile agent to prohibit the download of applications on mobile operating system devices without administrator control. If this function is not present, this is a finding.
Fix Text (F-40676r1_fix)
Configure the MDM server so the mobile device agent is configured to prohibit the download of applications on mobile operating system devices without system administrator control.