Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-24960 | WIR-SPP-005 | SV-30697r4_rule | ECWN-1 | High |
Description |
---|
DoDD 8100.2 states wireless devices will not be used for classified data unless approved for such use. Classified data could be exposed to unauthorized personnel. |
STIG | Date |
---|---|
Smartphone Policy Security Technical Implementation Guide | 2011-11-28 |
Check Text ( C-31119r3_chk ) |
---|
This requirement applies to mobile operating system (OS) smartphones and tablets. This requirement does not apply to the SME PED as it is the only smartphone approved for classified data use. Interview the IAO. Verify written policy and training material exists (or requirement is listed on a signed user agreement) stating smartphones must not be used to transmit classified information. Mark as a finding if written policy or training material does not exist, stating smartphones must not be used to transmit classified information. |
Fix Text (F-27587r1_fix) |
---|
Do not process, send, receive, or use classified data on smartphones. |