UCF STIG Viewer Logo

The MDM server device integrity validation component must support organizational requirements to address the receipt of false positives during malicious code detection.


Overview

Finding ID Version Rule ID IA Controls Severity
V-36177 SRG-APP-280-MDM-172-MDIS SV-47581r1_rule Medium
Description
In order to minimize potential negative impact to the organization that can be caused by malicious code, it is imperative that malicious code is identified and eradicated. Malicious code includes viruses, worms, Trojan horses, and Spyware. The MDM server must have an ability to address the issue of false alerts. False alerts can overwhelm reporting and administrative interfaces making it difficult to identify the true threat. A filtering capability that serves to identify and remove false positives is often employed to address this issue.
STIG Date
Mobile Device Manager Security Requirements Guide 2013-01-24

Details

Check Text ( C-44417r1_chk )
Review the MDM server configuration to ensure the MDM server device integrity validation component supports organizational requirements to address the receipt of false positives during malicious code detection. If this function is not present, this is a finding.
Fix Text (F-40707r1_fix)
Configure the MDM server device integrity validation component to support organizational requirements to address the receipt of false positives during malicious code detection.