Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36355 | SRG-APP-222-MDM-290-SRV | SV-47759r1_rule | Low |
Description |
---|
This requirement focuses on communications protection at the application session, versus network packet level. The intent of this control is to establish grounds for confidence at each end of a communications session in the ongoing identity of the other party and in the validity of the information being transmitted. This helps prevent a session hijacking attack. |
STIG | Date |
---|---|
Mobile Device Manager Security Requirements Guide | 2013-01-24 |
Check Text ( C-44597r1_chk ) |
---|
Review the MDM server configuration to determine whether the MDM server generates a unique session identifier for each session. Have an administrator log into the server and view the logs to verify a unique session identifier was assigned to the session. If the MDM server does not generate a unique session identifier for each session, this is a finding. |
Fix Text (F-40887r1_fix) |
---|
Configure that MDM server to generate a unique session identifier for each session. |