UCF STIG Viewer Logo

The MDM server must support and maintain the binding of digital signatures on information in transmission.


Overview

Finding ID Version Rule ID IA Controls Severity
V-36264 SRG-APP-008-MDM-237-SRV SV-47668r1_rule High
Description
Digital signatures enable the system to verify the integrity of the signed object and authenticate the object’s signatory. Failure to maintain the binding of digital signatures on software components and applications in process makes it more likely that an adversary could modify or replace those objects when the software is executed. The bindings enable the operating system to verify the software’s integrity and source just before the execution process. In order for the signature to be present at execution, it must be bound during transmission.
STIG Date
Mobile Device Manager Security Requirements Guide 2013-01-24

Details

Check Text ( C-44504r1_chk )
Review system configuration to determine whether the MDM server maintains the binding of digital signatures on information in transmission. If these bindings are not maintained, this is a finding.
Fix Text (F-40794r1_fix)
Configure the MDM server to maintain the binding of digital signatures on information in transmission.