UCF STIG Viewer Logo

The organization must develop policy to restrict smartphone Instant Messaging (IM) client applications to connect to only security-compliant, DoD-controlled IM servers.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-MPOL-052 SRG-MPOL-052 SRG-MPOL-052_rule Medium
Description
Non-DoD IM servers can be located anywhere in the world and may be under an adversary's control. If a DoD smartphone IM client connects to a non-DoD IM server, malware could be installed on the smartphone from the server, or sensitive DoD data on the smartphone could be transferred to the server. In addition, if malware is installed on the smartphone, this could lead to hacker attacks on the DoD enclave the smartphone connects to.
STIG Date
Mobile Policy Security Requirements Guide 2012-10-10

Details

Check Text ( C-SRG-MPOL-052_chk )
Determine if a policy is in place to ensure only DoD managed IM servers are used for the IM service on site-managed smartphones.

If a policy is not in place to ensure the IM server the smartphone IM applications connect to is not managed by a DoD site, this is a finding.
Fix Text (F-SRG-MPOL-052_fix)
Develop policy to ensure Instant Messaging (IM) client applications connect only to a security-compliant, DoD-controlled IM server.