UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The VPN client on wireless clients (PDAs, smartphones) used for remote access to DoD networks must be FIPS 140-2 validated.


Overview

Finding ID Version Rule ID IA Controls Severity
V-18627 WIR-MOS-PDA-034-01 SV-40039r1_rule ECWN-1 Medium
Description
DoD data could be compromised if transmitted data is not secured with a compliant VPN. FIPS validation provides a level of assurance that the encryption of the device has been securely implemented.
STIG Date
PDA/Smartphone Security Technical Implementation Guide 2011-10-07

Details

Check Text ( C-39052r1_chk )
Interview the IAO and/or site wireless device administrator and inspect a sample (3-4) of site devices. Review VPN client
specification sheets and FIPS 140-2 certificate. Verify the
devices have a VPN client installed and that it is FIPS 140-2
validated. Mark as a finding if the VPN is not FIPS 140-2
validated.
Fix Text (F-20573r2_fix)
Comply with policy requirement.