Search filters the loaded procedure list locally. Separate terms must all match (use quotes for an exact phrase). Cached STIG Search results apply when you arrive from Search.
Objective ID
Severity
Discussion
V-71627
medium
Having several roles for the MDM Server supports separation of duties. This allows administrator-level privileges to be granted granularly, such as giving application management privileges to one group and security policy privileges to another group. This helps prevent administrators from intentionally or inadvertently altering other settings and configurations they may not understand or approve of, which can weaken overall security and increase the risk of compromise.
Server primary administrator: responsible for server installation, initial configuration, and maintenance functions. Responsible for the setup and maintenance of Security configuration administrator and Auditor accounts. (Note: Many of these responsibilities are not AirWatch MDM Server Roles, but Host Operating System roles)
-Security configuration administrator: responsible for security configuration of the server, setting up and maintenance of mobile device security policies, defining device user groups, setup and maintenance of device user group administrator accounts, and defining privileges of device user group administrators. (Note: Many of these responsibilities are not AirWatch MDM Server Roles, but Host Operating System roles)
-Device user group administrator: responsible for maintenance of mobile device accounts, including setup, change of account configurations, and account deletion. Can only perform administrative functions assigned by the Security configuration administrator.
-Auditor: responsible for reviewing and maintaining server and mobile device audit logs. (Note: Many of these responsibilities are not AirWatch MDM Server Roles, but Host Operating System roles)
SFR ID: FMT_SMR.1.1(1) Refinement
Server primary administrator: responsible for server installation, initial configuration, and maintenance functions. Responsible for the setup and maintenance of Security configuration administrator and Auditor accounts. (Note: Many of these responsibilities are not AirWatch MDM Server Roles, but Host Operating System roles)
-Security configuration administrator: responsible for security configuration of the server, setting up and maintenance of mobile device security policies, defining device user groups, setup and maintenance of device user group administrator accounts, and defining privileges of device user group administrators. (Note: Many of these responsibilities are not AirWatch MDM Server Roles, but Host Operating System roles)
-Device user group administrator: responsible for maintenance of mobile device accounts, including setup, change of account configurations, and account deletion. Can only perform administrative functions assigned by the Security configuration administrator.
-Auditor: responsible for reviewing and maintaining server and mobile device audit logs. (Note: Many of these responsibilities are not AirWatch MDM Server Roles, but Host Operating System roles)
SFR ID: FMT_SMR.1.1(1) Refinement
V-71629
low
Mobile devices that do not enforce security policy or verify the status of the device are vulnerable to a variety of attacks. The key security function of MDM technology is to distribute mobile device security polices in such a manner that they are enforced on managed mobile devices. To accomplish this function, the AirWatch MDM Agent must verify the status and other key information of the managed device and report that status to the MDM server periodically.
SFR ID: FMT_SMF_EXT.3.2
SFR ID: FMT_SMF_EXT.3.2
V-71631
medium
Audit logs and alerts enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify when the security posture of the device is not as expected, including when critical or security relevant applications have not fully installed on mobile devices under management of the MDM platform. This enables the MDM administrator to take an appropriate remedial action.
SFR ID: FAU_ALT_EXT.2.1
SFR ID: FAU_ALT_EXT.2.1
V-71633
medium
Audit logs and alerts enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify when the security posture of the device is not as expected, including when a critical or security relevant application was not properly updated on mobile devices under management of the MDM platform. This enables the MDM administrator to take an appropriate remedial action.
SFR ID: FAU_ALT_EXT.2.1
SFR ID: FAU_ALT_EXT.2.1
V-71635
medium
Most information systems are capable of providing a wide variety of functions and services. Some of the functions and services provided by default may not be necessary to support essential organizational operations. Unneeded services and processes provide additional threat vectors and avenues of attack to the information system. The AirWatch MDM Server is a critical component of the mobility architecture and must be configured to only those ports, protocols, and services (PPS) necessary to support functionality, all others must be expressly disabled or removed. A DoD-approved firewall implements the required network restrictions. A host-based firewall is appropriate where the AirWatch MDM Server runs on a standalone platform. Network firewalls or other architectures may be preferred where the AirWatch MDM Server runs in a cloud or virtualized solution.
SFR ID: FMT_SMF.1.1(1) Refinement
SFR ID: FMT_SMF.1.1(1) Refinement
V-71637
medium
Most information systems are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizational operations. Since AirWatch MDM Server is a critical component of the mobility architecture and must be configured to only those ports, protocols, and services (PPS) necessary to support functionality, all others must be expressly disabled or removed. A firewall installed on the AirWatch MDM Server provides a protection mechanism to ensure unwanted service requests do not reach the AirWatch MDM Server and outbound traffic is limited to only AirWatch MDM Server functionality.
SFR ID: FMT_SMF.1.1(1) Refinement
SFR ID: FMT_SMF.1.1(1) Refinement
V-71645
medium
A comprehensive account management process that includes automation helps to ensure the accounts designated as requiring attention are consistently and promptly addressed. If an attacker compromises an account, the entire MDM Server infrastructure is at risk. Providing automated support functions for the management of accounts will ensure only active accounts will be granted access with the proper authorization levels. These objectives are best achieved by configuring the AirWatch MDM Server to leverage an enterprise authentication mechanism (e.g., Microsoft Active Directory Kerberos).
SFR ID: FIA
SFR ID: FIA
V-99999
high
AirWatch Console/Workspace One UEM Console version 9.7 and earlier releases are no longer supported by VMware and therefore, may contain security vulnerabilities. AirWatch Console/Workspace One UEM Console version 9.7 and earlier releases are not authorized within the DoD.
CCI: CCI-000366
CCI: CCI-000366