UCF STIG Viewer Logo

The organization must not use mobile operating system (OS) based smartphone and tablet devices and systems to send, receive, store, or process classified messages unless specifically approved by NSA for such purposes and NSA-approved transmission and storage methods are used.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-MPOL-065 SRG-MPOL-065 SRG-MPOL-065_rule High
Description
Wireless devices will not be used for processing classified data unless approved for such use as classified data could be compromised or exposed to unauthorized personnel.
STIG Date
Mobile Policy Security Requirements Guide 2012-10-10

Details

Check Text ( C-SRG-MPOL-065_chk )
Verify written policy and training material exists (or requirement is listed on a signed user agreement) stating smartphones/tablets must not be used to transmit classified information.

If written policy or training material, stating smartphones/tablets must not be used to receive, transmit, or process classified information, does not exist, this is a finding.
Fix Text (F-SRG-MPOL-065_fix)
Ensure smartphones are not utilized to process, send, receive, or store classified data.