STIGQter STIGQter: STIG Summary: MDM Server Policy Security Technical Implementation Guide (STIG) Version: 2 Release: 5 Benchmark Date: 26 Jul 2019:

The mobile device management (MDM) server administrator must receive required training.

DISA Rule

SV-30707r7_rule

Vulnerability Number

V-24970

Group Title

MDM server administrator training

Rule Version

WIR-WMSP-001-01

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Have MDM server administrator complete and document his/her training.

Check Contents

Detailed policy requirements:
The MDM server administrator must be trained on the following requirements:

- Requirement that administrative service accounts will not be used to log into the mobile device management server or any server service.

- Activation passwords or PINs will consist of a pseudo-random pattern of at least eight characters consisting of at least two letters and two numbers. A new activation password must be selected each time one is assigned (e.g., the same password cannot be used for all users or for a group of users).

- User and group accounts on the MDM server will always be assigned a STIG-compliant security/IT policy.

Check procedures:
-Verify the MDM server administrator(s) has received the required training. The site should document when the training was completed.

If the MDM server administrator did not receive required training, this is a finding.

Vulnerability Number

V-24970

Documentable

False

Rule Version

WIR-WMSP-001-01

Severity Override Guidance

Detailed policy requirements:
The MDM server administrator must be trained on the following requirements:

- Requirement that administrative service accounts will not be used to log into the mobile device management server or any server service.

- Activation passwords or PINs will consist of a pseudo-random pattern of at least eight characters consisting of at least two letters and two numbers. A new activation password must be selected each time one is assigned (e.g., the same password cannot be used for all users or for a group of users).

- User and group accounts on the MDM server will always be assigned a STIG-compliant security/IT policy.

Check procedures:
-Verify the MDM server administrator(s) has received the required training. The site should document when the training was completed.

If the MDM server administrator did not receive required training, this is a finding.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

3519

Comments