Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36350 | SRG-APP-144-MDM-287-MDIS | SV-47754r1_rule | High |
Description |
---|
Since the MDM server controls many mobile devices as well as serving as a gateway into the network infrastructure, the absence of this feature could also enable an adversary to launch an enterprise-wide DoS attack. |
STIG | Date |
---|---|
Mobile Device Manager Security Requirements Guide | 2013-01-24 |
Check Text ( C-44592r1_chk ) |
---|
Review MDM server documentation and determine if the MDM server provides transaction recovery to avoid disabling the CMD in the event of an incomplete policy push. If the MDM server does not provide transaction recovery to avoid disabling the CMD in the event of an incomplete policy push, this is a finding. |
Fix Text (F-40882r1_fix) |
---|
Configure the MDM server to provide transaction recovery to avoid disabling the CMD in the event of an incomplete policy push. |