Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-33067 | SRG-OS-000103-MOS-000065 | SV-43465r1_rule | High |
Description |
---|
The operating system must enforce software installation by users based upon what types of software installations are permitted (e.g., updates and security patches to existing software) and what types of installations are prohibited (e.g., software whose pedigree with regard to being potentially malicious is unknown or suspect) by the organization. The installation and execution of unauthorized software on an operating system may allow the application to obtain sensitive information or further compromise the system. Preventing a user from installing unapproved applications mitigates this risk. |
STIG | Date |
---|---|
Mobile Operating System Security Requirements Guide | 2013-07-03 |
Check Text ( C-41335r1_chk ) |
---|
Review the mobile operating system configuration to determine if controls prevent a user from installing unapproved applications. If controls are not present to prevent a user from installing unapproved applications, this is a finding. |
Fix Text (F-36968r2_fix) |
---|
Configure the mobile operating system to prevent a user from installing unapproved applications. |