Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-25009 | WIR-MOS-PDA-013 | SV-31263r2_rule | ECWN-1 IAIA-1 | Low |
Description |
---|
If the passcode is not changed periodically, then an adversary with knowledge of the passcode can use it indefinitely without detection, potentially allowing access to sensitive DoD information and enabling subsequent attacks. |
STIG | Date |
---|---|
PDA/Smartphone Security Technical Implementation Guide | 2011-10-07 |
Check Text ( C-31671r1_chk ) |
---|
Check a sample (3-4 devices) of site PDAs and verify the password age is set to 90 days or less. |
Fix Text (F-27659r2_fix) |
---|
Set maximum passcode age as required. |