Unified Endpoint Management Agent Security Requirements Guide

14procedures

Search filters the loaded procedure list locally. Separate terms must all match (use quotes for an exact phrase). Cached STIG Search results apply when you arrive from Search.

Severity
CurrentPublished Mon Jun 29 2026
Objective ID
Severity
Discussion
V-234235
medium
Alerts providing notification of a change in enrollment state facilitate verification of the correct operation of security functions. When an UEM server receives such an alert from an UEM Agent, it indicates the security policy may no longer be enforced on the mobile device. This enables the UEM administrator to take an appropriate remedial action.

Satisfies: FAU_ALT_EXT.2.1
Reference: PP-MDMA-200100, PP-MDMA-200200, PP-MDMA-200300
V-234236
medium
Without the capability to generate audit records, it would be difficult to establish, correlate, and investigate the events relating to an incident, or identify those responsible for one.

Audit records can be generated from various components within the application (e.g., process, module). Certain specific application functionalities may be audited as well. The list of audited events is the set of events for which audits are to be generated. This set of events is typically a subset of the list of all events for which the system is capable of generating audit records.

DoW has defined the list of events for which the application will provide an audit record generation capability as the following:

(i) Successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g., classification levels);

(ii) Access actions, such as successful and unsuccessful logon attempts, privileged activities or other system level access, starting and ending time for user access to the system, concurrent logons from different workstations, successful and unsuccessful accesses to objects, all program initiations, and all direct access to the information system; and

(iii) All account creation, modification, disabling, and termination actions.

DoW Required auditable events include:
- Change in enrollment status
- Failure to apply policies to a mobile device
- Start up and shut down of the MDM System
- All administrative actions
- Commands issued to the MDM Agent.

Satisfies: FAU_GEN.1.1/AGENT
V-234237
medium
Audit logs and alerts enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify when the security posture of the device is not as expected. This enables the UEM administrator to take an appropriate remedial action.

Satisfies: FMT_SMF_EXT.4.1
Reference: PP-MDMA-200700
V-234238
medium
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. For audit logs to be useful, administrators must have the ability to view them.

Satisfies: FAU_GEN.1.2/AGENT
V-234239
medium
It is critical that the UEM agent only use validated certificates for policy updates. Otherwise, there is no assurance that a malicious actor has not inserted itself in the process of packaging the code or policy.

Satisfies: FMT_POL_EXT.2.2
V-234240
medium
If validated secure storage locations are not used for keys, they could be compromised.

Satisfies: FCS_STG_EXT.4.1
V-234241
medium
Alerts providing notification of a change in enrollment state facilitate verification of the correct operation of security functions. When an UEM server receives such an alert from an UEM Agent, it indicates the security policy may no longer be enforced on the mobile device. This enables the UEM administrator to take an appropriate remedial action.

Satisfies: FAU_ALT_EXT.2.2
V-234242
medium
Audit logs and alerts enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify when the security posture of the device is not as expected. This enables the UEM administrator to take an appropriate remedial action. MD audit logs must be transferred to an audit management service so they can be analyzed and acted on.

Satisfies: FMT_SMF_EXT.4.1
Reference: PP-MDMA-200800
V-234243
medium
It is critical that the UEM agent only use validated certificates for policy updates. Otherwise, there is no assurance that a malicious actor has not inserted itself in the process of packaging the code or policy.

Satisfies: FMT_POL_EXT.2.1
V-234244
medium
It is critical that the UEM agent only use validated certificates for policy updates. Otherwise, there is no assurance that a malicious actor has not inserted itself in the process of packaging the code or policy.

Satisfies: FMT_SMF_EXT.4.1
V-234245
medium
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. For audit logs to be useful, administrators must have the ability to view them.

Satisfies: FIA_ENR_EXT.2.1
V-234246
medium
Access control of mobile devices to DoW sensitive information or access to DoW networks must be controlled so that DoW data will not be compromised. The primary method of access control of mobile devices is via enrollment of authorized mobile devices on the UEM server. Therefore, the UEM server must have the capability to enforce a policy for this control.

Satisfies: FMT_SMF_EXT.4.2
V-234247
medium
Access control of mobile devices to DoW sensitive information or access to DoW networks must be controlled so that DoW data will not be compromised. The primary method of access control of mobile devices is via enrollment of authorized mobile devices on the UEM server. Therefore, the UEM server must have the capability to enforce a policy for this control.

Satisfies: FMT_UNR_EXT.1.1
V-234248
high
Unapproved cryptographic algorithms cannot be relied on to provide confidentiality or integrity, and DoW data could be compromised as a result. The most common vulnerabilities with cryptographic modules are those associated with poor implementation. FIPS 140-3 validation provides assurance that the relevant cryptography has been implemented correctly. FIPS 140-3 validation is also a strict requirement for use of cryptography in the federal government for protecting unclassified data.

This requirement also applies to Zero Trust initiatives.

Satisfies: FCS
Reference: PP-MDMA-200600