Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36363 | SRG-APP-143-MDM-295-SRV | SV-47767r1_rule | Medium |
Description |
---|
Information systems are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizational operations (e.g., key missions, functions). Unneeded services and processes provide additional threat vectors and avenues of attack to the information system. |
STIG | Date |
---|---|
Mobile Device Manager Security Requirements Guide | 2013-01-24 |
Check Text ( C-44605r1_chk ) |
---|
Review the MDM server configuration to determine whether the MDM server can disable services that are not required by site-defined functions. If services cannot be disabled, this is a finding. |
Fix Text (F-40895r1_fix) |
---|
Configure the MDM server to use only the services required by site defined functions. |