Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-24970 | WIR-WMSP-001 | SV-30707r1_rule | PRTN-1 | Low |
Description |
---|
The security posture of the smartphone management server could be compromised if the admin is not trained to follow required procedures. |
STIG | Date |
---|---|
Wireless Management Server Policy Security Technical Implementation Guide | 2011-01-06 |
Check Text ( C-31134r1_chk ) |
---|
Detailed policy requirements: The smartphone management server admin must be trained on the following requirements: -Requirement that administrative service accounts will not be used to log into the smartphone management server or any server service. -Activation passwords or PINs will consist of a pseudo-random pattern of at least eight characters consisting of at least two letters and two numbers. A new activation password must be selected each time one is assigned (e.g., the same password cannot be used for all users or for a group of users). - User and group accounts on the smartphone management server will always be assigned a STIG-compliant security/IT policy. -Training will be renewed annually. Check procedures: - Verify the smartphone management server administrator(s) has received the required training. The site should document when the training was completed. - Verify training is renewed annually. |
Fix Text (F-27604r1_fix) |
---|
Have smartphone management server administrator complete and document his/her training. |