Review the organization's access control and security policy, list of officials with authority to approve the connection of unclassified mobile devices to unclassified information systems, procedures addressing access control for portable and mobile devices, documentation for random inspections of mobile devices, and other relevant documents or records. Interview organizational personnel responsible for granting approval to connect unclassified mobile devices to unclassified information systems; organization personnel responsible for randomly reviewing/inspecting mobile devices; and organizational personnel using mobile devices in facilities containing information systems processing, storing, or transmitting classified information. Verify (i) the organization has developed and published an access control security policy requiring approval to connect unclassified mobile devices to unclassified information systems by nominated organization officials; and (ii) the organization has identified organization personnel with the authority to grant connection approval.
If a policy requiring connection approval does not exist, this is a finding. |