UCF STIG Viewer Logo

The MDM server application white list for managed mobile devices must be set to Deny All by default when no applications are listed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-36147 SRG-APP-135-MDM-147-MAM SV-47551r1_rule High
Description
The installation and execution of unauthorized software on an operating system may allow the application to obtain sensitive information or further compromise the system. If the system administrator has control over what applications are downloaded, then the system administrator can check that only known good programs are installed, which significantly mitigates the risk posed by malicious software.
STIG Date
Mobile Device Manager Security Requirements Guide 2013-01-24

Details

Check Text ( C-44387r1_chk )
Review the MDM server configuration to ensure the MDM server application white list for managed mobile devices is set to "Deny All" by default when no applications are listed. If configuration is set to other than "Deny All," or if the MDM server does not have an application whitelist, this is a finding.
Fix Text (F-40677r1_fix)
Configure the MDM server application white list for managed mobile devices to "Deny All" by default when no applications are listed.