Search filters the loaded procedure list locally. Separate terms must all match (use quotes for an exact phrase). Cached STIG Search results apply when you arrive from Search.
Objective ID
Severity
Discussion
V-260397
medium
DOD policy requires BYOAD devices with DOD data be managed by a DOD MDM server, MAM server, or VMI system. This ensures the device can be monitored for compliance with the approved security baseline and the work profile can be removed when the device is out of compliance, which protects DOD data from unauthorized exposure.
Examples of possible EMM security controls are as follows:
1. Device access restrictions: Restrict or isolate access based on the devices access type (i.e., from the internet), authentication type (e.g., password), credential strength, etc.
2. User and device activity monitoring: Configured to detect anomalous activity, malicious activity, and unauthorized attempts to access DOD information.
3. Device health tracking: Monitor device attestation, health, and agents reporting compromised applications, connections, intrusions, and/or signatures.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)ii, 3.b.(2)ii.1 & 2).
SFR ID: FMT_SMF_EXT.1.1 #47
Examples of possible EMM security controls are as follows:
1. Device access restrictions: Restrict or isolate access based on the devices access type (i.e., from the internet), authentication type (e.g., password), credential strength, etc.
2. User and device activity monitoring: Configured to detect anomalous activity, malicious activity, and unauthorized attempts to access DOD information.
3. Device health tracking: Monitor device attestation, health, and agents reporting compromised applications, connections, intrusions, and/or signatures.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)ii, 3.b.(2)ii.1 & 2).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260398
medium
DOD policy requires BYOAD devices with DOD data be managed by a DOD MDM server, MAM server, or VMI system. This ensures the device can be monitored for compliance with the approved security baseline and the work profile can be removed when the device is out of compliance, which protects DOD data from unauthorized exposure.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260399
medium
Examples of indicators that the native device native security controls have been disabled include jailbroken or rooted devices.
DOD policy requires BYOAD devices with DOD data be managed by a DOD MDM server, MAM server, or VMI system. This ensures the device can be monitored for compliance with the approved security baseline and the work profile can be removed when the device is out of compliance, which protects DOD data from unauthorized exposure. Detection via collecting and analysis of BYOAD generated logs for noncompliance indicators is acceptable.
This detection capability must be implemented prior to BYOAD access to DOD information and IT resources and continuously monitored on the DOD-managed segment of the BYOAD enrolled in the program. If non-DOD information (i.e., personal user data, device information) outside the DOD-managed segment of the BYOAD is required to be accessed, collected, monitored, tracked (i.e., location), or maintained, the circumstances under which this may be done must be outlined in the user agreement.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
DOD policy requires BYOAD devices with DOD data be managed by a DOD MDM server, MAM server, or VMI system. This ensures the device can be monitored for compliance with the approved security baseline and the work profile can be removed when the device is out of compliance, which protects DOD data from unauthorized exposure. Detection via collecting and analysis of BYOAD generated logs for noncompliance indicators is acceptable.
This detection capability must be implemented prior to BYOAD access to DOD information and IT resources and continuously monitored on the DOD-managed segment of the BYOAD enrolled in the program. If non-DOD information (i.e., personal user data, device information) outside the DOD-managed segment of the BYOAD is required to be accessed, collected, monitored, tracked (i.e., location), or maintained, the circumstances under which this may be done must be outlined in the user agreement.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260400
medium
DOD policy requires BYOAD devices with DOD data be managed by a DOD MDM server, MAM server, or VMI system. This ensures the device can be monitored for compliance with the approved security baseline and the work profile can be removed when the device is out of compliance, which protects DOD data from unauthorized exposure. Detection via collecting and analysis of BYOAD generated logs for noncompliance indicators is acceptable.
This detection capability must be implemented prior to AMD (Approved Mobile Device, called BYOAD device in the STIG) enrollment, AMD access to DOD information and IT resources, and continuously monitored on the DOD-managed segment of the AMD enrolled in the program. If non-DOD information (i.e., personal user data, device information) outside the DOD-managed segment of the AMD is required to be accessed, collected, monitored, tracked (i.e., location), or maintained, the circumstances under which this may be done must be outlined in the user agreement.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
This detection capability must be implemented prior to AMD (Approved Mobile Device, called BYOAD device in the STIG) enrollment, AMD access to DOD information and IT resources, and continuously monitored on the DOD-managed segment of the AMD enrolled in the program. If non-DOD information (i.e., personal user data, device information) outside the DOD-managed segment of the AMD is required to be accessed, collected, monitored, tracked (i.e., location), or maintained, the circumstances under which this may be done must be outlined in the user agreement.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260401
medium
DOD policy requires BYOAD devices with DOD data be managed by a DOD MDM server, MAM server, or VMI system. This ensures the device can be monitored for compliance with the approved security baseline and the work profile can be removed when the device is out of compliance, which protects DOD data from unauthorized exposure. Continuous monitoring must be used to ensure all noncompliance events will be seen by the detection system.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260402
medium
Examples of indicators that the native device security controls have been disabled include jailbroken or rooted devices.
When a BYOAD is out of compliance, DOD data and apps must be removed to protect against compromise of sensitive DOD information.
Note: The site should review DOD and local data retention policies before wiping the work profile of a BYOAD device.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.b.(4) 3.b.(5)i).
SFR ID: FMT_SMF_EXT.1.1 #47
When a BYOAD is out of compliance, DOD data and apps must be removed to protect against compromise of sensitive DOD information.
Note: The site should review DOD and local data retention policies before wiping the work profile of a BYOAD device.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.b.(4) 3.b.(5)i).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260403
medium
When a BYOAD is out of compliance, DOD data and apps must be removed to protect against compromise of sensitive DOD information.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)iii).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260404
medium
When a BYOAD is out of compliance, DOD data and apps must be removed to protect against compromise of sensitive DOD information.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.b.(1)ii).
SFR ID: FMT_SMF_EXT.1.1 #47
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.b.(1)ii).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260405
high
Note: IT resources includes DOD networks and applications (for example, DOD email).
The system administrator must have the capability to limit access of the BYOAD to DOD networks and DOD IT resources based on mission needs and risk. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. The AO should document networks, IT resources, and enterprise applications that BYOAD can access.
Examples of EMM security controls are as follows:
1. Device access restrictions: Restrict or isolate access based on the devices access type (i .e., from the internet), authentication type (e.g., password), credential strength, etc.
2. User and device activity monitoring: Configured to detect anomalous activity, malicious activity, and unauthorized attempts to access DOD information.
3. Device health tracking: Monitor device attestation, health, and agents reporting compromised applications, connections, intrusions, and/or signatures.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.b.(2)ii).
SFR ID: FMT_SMF_EXT.1.1 #47
The system administrator must have the capability to limit access of the BYOAD to DOD networks and DOD IT resources based on mission needs and risk. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. The AO should document networks, IT resources, and enterprise applications that BYOAD can access.
Examples of EMM security controls are as follows:
1. Device access restrictions: Restrict or isolate access based on the devices access type (i .e., from the internet), authentication type (e.g., password), credential strength, etc.
2. User and device activity monitoring: Configured to detect anomalous activity, malicious activity, and unauthorized attempts to access DOD information.
3. Device health tracking: Monitor device attestation, health, and agents reporting compromised applications, connections, intrusions, and/or signatures.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.b.(2)ii).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260406
high
Note: For a VMI solution, both the client and server must be NIAP compliant.
Nonapproved EMM systems may not include sufficient controls to protect work data, applications, and networks from malware or adversary attack. EMM: mobile device management (MDM), mobile application management (MAM), mobile content management (MCM), or virtual mobile infrastructure (VMI).
Components must only approve devices listed on the NIAP product compliant list or products listed in evaluation at the following links respectfully:
- https://www.niap-ccevs.org/Product/
- https://www.niap-ccevs.org/Product/PINE.cfm
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(2)).
SFR ID: FMT_SMF_EXT.1.1 #47
Nonapproved EMM systems may not include sufficient controls to protect work data, applications, and networks from malware or adversary attack. EMM: mobile device management (MDM), mobile application management (MAM), mobile content management (MCM), or virtual mobile infrastructure (VMI).
Components must only approve devices listed on the NIAP product compliant list or products listed in evaluation at the following links respectfully:
- https://www.niap-ccevs.org/Product/
- https://www.niap-ccevs.org/Product/PINE.cfm
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(2)).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260407
low
DOD policy states BYOAD owners must sign a user agreement and be made aware of what personal data and activities will be monitored by the Enterprise by including this information in the user agreement.
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)ii, and 3.c.(4)).
SFR ID: FMT_SMF_EXT.1.1 #47
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)ii, and 3.c.(4)).
SFR ID: FMT_SMF_EXT.1.1 #47
V-260408
medium
DOD policy requires BYOAD devices with DOD data be managed by a DOD MDM server, MAM server, or VMI system. This ensures the device can be monitored for compliance with the approved security baseline and the work profile can be removed when the device is out of compliance, which protects DOD data from unauthorized exposure.
Follow local physical security procedures regarding allowing or prohibiting personally owned mobile devices in a DOD facility. If BYOAD devices are brought into facilities where the AO has determined the risk of using personal devices is unacceptable, this could lead to the exposure of sensitive DOD data.
SFR ID: FMT_SMF_EXT.1.1 #47
Follow local physical security procedures regarding allowing or prohibiting personally owned mobile devices in a DOD facility. If BYOAD devices are brought into facilities where the AO has determined the risk of using personal devices is unacceptable, this could lead to the exposure of sensitive DOD data.
SFR ID: FMT_SMF_EXT.1.1 #47
V-260409
medium
In some DOD operational environments, the use of the mobile device camera or microphone could lead to a security incident or compromise of DOD information. The System Administrator must have the capability to disable the mobile device camera and/or microphone based on mission needs. Alternatively, mobile devices with cameras or microphones that cannot be disabled must be prohibited from the facility by the ISSO/ISSM.
If BYOAD devices are brought into facilities where the AO has determined the risk of using mobile device cameras or microphones is unacceptable, this could lead to the exposure of sensitive DOD data.
SFR ID: FMT_SMF_EXT.1.1 #47
If BYOAD devices are brought into facilities where the AO has determined the risk of using mobile device cameras or microphones is unacceptable, this could lead to the exposure of sensitive DOD data.
SFR ID: FMT_SMF_EXT.1.1 #47
V-260410
high
Nonapproved mobile devices may not include sufficient controls to protect work data, applications, and networks from malware or adversary attack.
Components must only approve devices listed on the NIAP product compliant list or products listed in evaluation at the following links respectfully:
- https://www.niap-ccevs.org/Product/
- https://www.niap-ccevs.org/Product/PINE.cfm
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.b.(1)i).
SFR ID: FMT_SMF_EXT.1.1 #47
Components must only approve devices listed on the NIAP product compliant list or products listed in evaluation at the following links respectfully:
- https://www.niap-ccevs.org/Product/
- https://www.niap-ccevs.org/Product/PINE.cfm
Reference: DOD policy "Use of Non-Government Mobile Devices" (3.b.(1)i).
SFR ID: FMT_SMF_EXT.1.1 #47
V-282966
Samsung Android 14 BYOAD is no longer supported by Samsung and may contain security vulnerabilities.
Satisfies: FMT_MOF_EXT.1.2 #47
Reference: PP-BYO-000110
Satisfies: FMT_MOF_EXT.1.2 #47
Reference: PP-BYO-000110