UCF STIG Viewer Logo

The organization must include each wireless device connecting to a DoD network in the applicable site security plan or other appropriate DIACAP document.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35948 SRG-MPOL-030 SV-47264r2_rule Low
Description
The DAA and site commander must be aware of all approved wireless devices used at the site or DoD data may be exposed to unauthorized individuals. Documentation of the enclave configuration must include all attached systems. If the current configuration cannot be determined, then it is difficult to apply security policies effectively. Security is particularly important for wireless technologies attached to the enclave network because these systems increase the potential for eavesdropping and other unauthorized access to network resources.
STIG Date
Mobile Policy Security Requirements Guide 2013-07-03

Details

Check Text ( C-44185r3_chk )
Review the site security plan. Wireless network devices, such as access points, laptops, CMDs, and wireless peripherals (keyboards, pointers, etc.) using a wireless network protocol, such as Bluetooth, Wi-Fi, or proprietary protocols must be documented in the site security plan. A general statement in the site security plan permitting the various types of wireless network devices used by the site is acceptable rather than a by-model listing, for example, "wireless devices of various models are permitted as long as they are configured in accordance with the Wireless STIG". If a DAA-approved site security plan does not exist or if it has not been updated, this is a finding.
Fix Text (F-40473r2_fix)
Update the site security plan to include all devices connecting directly or indirectly (data synchronization) to the network.