Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36158 | SRG-APP-161-MDM-158-MDM | SV-47562r1_rule | Medium |
Description |
---|
Device authentication is a solution enabling an organization to manage both users and devices. This requirement applies to MDM servers that provide mobile device and user access to network shares, web servers, and other network resources located on the internal enclave (back-office servers, etc.). This connection bypasses user network authentication mechanisms (i.e., CAC authentication). Therefore, the MDM server must support CAC authentication of the user to back-office network resources, or disable access. |
STIG | Date |
---|---|
Mobile Device Manager Security Requirements Guide | 2013-01-24 |
Check Text ( C-44398r1_chk ) |
---|
Review the MDM server configuration to ensure the MDM server denies all connections to DoD network servers by managed mobile devices unless the MDM server can support PKI based mutual authentication between the network server and the mobile device user. If this function is not configured, this is a finding. |
Fix Text (F-40688r1_fix) |
---|
If the MDM server cannot support PKI based mutual authentication between the network server and the mobile device user, configure the MDM server to deny all connections to DoD network servers by managed mobile devices. |