Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-234235 | SRG-APP-000089-UEM-100002 | SV-234235r617416_rule | Medium |
Description |
---|
Alerts providing notification of a change in enrollment state facilitate verification of the correct operation of security functions. When an UEM server receives such an alert from an UEM Agent, it indicates the security policy may no longer be enforced on the mobile device. This enables the UEM administrator to take an appropriate remedial action. Satisfies: FAU_ALT_EXT.2.1 Reference: PP-UEM-402001, PP-UEM-402002, PP-MDM-402003 |
STIG | Date |
---|---|
Unified Endpoint Management Agent Security Requirements Guide | 2020-12-14 |
Check Text ( C-37420r617416_chk ) |
---|
Verify the UEM Agent provides an alert via the trusted channel to the UEM Server in the event of any of the following audit events: -successful application of policies to a mobile device -receiving or generating periodic reachability events -change in enrollment state -failure to install an application from the UEM Server -failure to update an application from the UEM Server. If the UEM Agent does not provide an alert via the trusted channel to the UEM Server in the event of any of the following audit events: -successful application of policies to a mobile device -receiving or generating periodic reachability events -change in enrollment state -failure to install an application from the UEM Server -failure to update an application from the UEM Server this is a finding. |
Fix Text (F-37385r617388_fix) |
---|
Configure the UEM Agent to provide an alert via the trusted channel to the UEM Server in the event of any of the following audit events: -successful application of policies to a mobile device -receiving or generating periodic reachability events -change in enrollment state -failure to install an application from the UEM Server -failure to update an application from the UEM Server. |