UCF STIG Viewer Logo

The mobile operating system must not include authentication credentials or other sensitive information in audit records.


Overview

Finding ID Version Rule ID IA Controls Severity
V-33198 SRG-OS-000205-NA SV-43597r1_rule Medium
Description
Any operating system providing too much information in error logs and in administrative messages to the screen, risks compromising the data and security of the structure and content of error messages needs to be carefully considered by the organization. Rationale for non-applicability: Resource constraints on mobile devices preclude implementation of all IA functions. The applicability of this control may be reconsidered at a future date if subsequent generations of mobile devices are better able to support this control and the applications and data typically on the device justify its implementation.
STIG Date
Mobile Operating System Security Requirements Guide 2013-07-03

Details

Check Text ( C-41460r1_chk )
This requirement is NA for the Mobile OS SRG.
Fix Text (F-37100r1_fix)
The requirement is NA. No fix is required.