BlackBerry PlayBook OS V2.1 Security Technical Implementation Guide

Developed by BlackBerry Ltd. in coordination with DISA for use in the DoD. Comments or proposed revisions to this document should be sent via e-mail to the following address: [email protected]

Details

Version / Release: V1R2

Published: 2014-08-29

Updated At: 2018-09-23 12:16:06

Actions

Download

Filter


Findings
Severity Open Not Reviewed Not Applicable Not a Finding
Overall 0 0 0 0
Low 0 0 0 0
Medium 0 0 0 0
High 0 0 0 0
Drop CKL or SCAP (XCCDF) results here.

    Vuln Rule Version CCI Severity Title Description Status Finding Details Comments
    SV-50508r1_rule PB21-00-000100 CCI-000056 MEDIUM BlackBerry PlayBook OS must retain the lock work space until the user reestablishes access using established identification and authentication procedures. The device lock function prevents further access to the system by initiating a session lock after a period of inactivity or upon receiving a request from a user. The device lock is retained until the user reestablishes access using established identificat
    SV-50509r1_rule PB21-00-000110 CCI-000056 MEDIUM BlackBerry PlayBook OS must retain the device lock until the user reestablishes access using established identification and authentication procedures. The device lock function prevents further access to the system by initiating a session lock after a period of inactivity or upon receiving a request from a user. The device lock is retained until the user reestablishes access using established identificat
    SV-50510r1_rule PB21-00-000120 CCI-000057 MEDIUM BlackBerry PlayBook OS must lock the device after no more than 15 minutes of inactivity. The device lock function prevents further access to the system by initiating a session lock after a period of inactivity or upon receiving a request from a user. The device lock is retained until the user reestablishes access using established identificat
    SV-50511r1_rule PB21-00-000130 CCI-000160 LOW BlackBerry PlayBook OS must synchronize the internal clock at least once every 24 hours with an authoritative time server or the Global Positioning System. Determining the correct time a particular application event occurred on a system is critical when conducting forensic analysis and investigating system events. Periodically synchronizing internal clocks with an authoritative time source is needed in ord
    SV-50512r1_rule PB21-00-000140 CCI-000192 MEDIUM BlackBerry PlayBook OS must disallow the device unlock password from containing fewer than a specified minimum number of upper case alphabetic characters, lower case alphabetic characters, and numeric characters. Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute force attack. Setting minimum numbers of certain types of characters increases password complexity, and therefore makes it more difficult for
    SV-50513r1_rule PB21-00-000150 CCI-000193 MEDIUM BlackBerry PlayBook OS must disallow the device unlock password from containing fewer than a specified minimum number of lower case alphabetic characters. Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute force attack. Setting minimum numbers of certain types of characters increases password complexity, and therefore makes it more difficult for
    SV-50514r1_rule PB21-00-000160 CCI-000194 MEDIUM BlackBerry PlayBook OS must disallow the device unlock password from containing fewer than a specified minimum number of numeric characters. Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute force attack. Setting minimum numbers of certain types of characters increases password complexity, and therefore makes it more difficult for
    SV-50515r1_rule PB21-00-000170 CCI-000199 LOW BlackBerry PlayBook OS must enforce a maximum lifetime of 120 days for the device unlock password (password age). Changing passcodes regularly prevents an attacker who has compromised the password from re-using it to regain access. This is an unlikely scenario, but is addressed by setting a password expiration. The IA control only needs to be enforced in product leve
    SV-50516r1_rule PB21-00-000180 CCI-000200 LOW BlackBerry PlayBook OS must prohibit a user from reusing any of the last five previously used device unlock passwords. Password complexity, or strength, is a measure of the effectiveness of a password in resisting guessing and brute force attacks. Remembering the prior five device unlock passwords enables the operating system from permitting those passwords to be reused,
    SV-50517r1_rule PB21-00-000190 CCI-000205 MEDIUM BlackBerry PlayBook OS must enforce a minimum length for the work area password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting guessing and brute force attacks. The ability to crack a password is a function of how many times an attempt to crack the password, how quickly the adversary ca
    SV-50542r1_rule PB21-00-000200 CCI-000205 LOW BlackBerry PlayBook OS must enforce a minimum length for the device unlock password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting guessing and brute force attacks. The ability to crack a password is a function of how many times an attempt to crack the password, how quickly the adversary ca
    SV-50543r1_rule PB21-00-000210 CCI-000381 HIGH BlackBerry PlayBook OS must not permit mobile service carriers to have privileged access to the operating system or perform any function not directed by the user. Permitting mobile service carriers access to the mobile operating system leaves the device vulnerable to breach from rogue elements within the carrier infrastructure. Mobile service carriers are not subject to the same personnel, operational, and technica
    SV-50544r1_rule PB21-00-000220 CCI-000663 HIGH BlackBerry PlayBook OS must prevent a user from installing applications from an untrusted source (other than BlackBerry World) in the personal space. The operating system must enforce software installation by users based upon what types of software installations are permitted (e.g., updates and security patches to existing software) and what types of installations are prohibited (e.g., software whose p
    SV-50545r1_rule PB21-00-000230 CCI-000663 MEDIUM BlackBerry PlayBook OS must only permit download of software from a DoD approved source (e.g., DoD operated mobile device application store or MDM server). DoD can perform due diligence on sources of software to mitigate the risk that malicious software is introduced to those sources. Therefore, if software is downloaded from a DoD approved source, then it is less likely to be malicious than if it is downloa
    SV-50546r1_rule PB21-00-000240 CCI-000780 MEDIUM BlackBerry PlayBook OSs Wi-Fi module must use EAP-TLS authentication when authenticating to DoD WLAN authentication servers. Without strong mutual authentication a mobile device may connect to an unauthorized network. In many cases, the user may falsely believe that the device is connected to an authorized network and then provide authentication credentials and other sensitive
    SV-50547r1_rule PB21-00-000250 CCI-000780 MEDIUM BlackBerry PlayBook OS must authenticate devices before establishing remote network (e.g., VPN) connections using bidirectional cryptographically based authentication between devices. Without strong mutual authentication a mobile device may connect to an unauthorized network. In many cases, the user may falsely believe that the device is connected to an authorized network and then provide authentication credentials and other sensitive
    SV-50548r1_rule PB21-00-000260 CCI-000780 MEDIUM BlackBerry PlayBook OS VPN client must employ DoD PKI approved mechanisms for authentication when connecting to DoD networks. VPNs are vulnerable to attack if they are not supported by strong authentication. An adversary may be able gain access to network resources and sensitive information if they can compromise the authentication process. Common Access Card (CAC) authenticatio
    SV-50549r1_rule PB21-00-000270 CCI-001130 MEDIUM BlackBerry PlayBook OSs VPN client must use either IPSec or SSL/TLS when connecting to DoD networks. Use of non-standard communications' protocols can affect both the availability and confidentiality of communications. IPSec and SSL/TLS are both well-known and tested protocols that provide strong assurance with respect to both IA and interoperability.
    SV-50551r1_rule PB21-00-000290 CCI-001154 MEDIUM BlackBerry PlayBook OS must prohibit the use of non-DoD authorized instant messaging (IM) systems. Many instant messaging systems have known vulnerabilities, some of which allow an adversary to install malware on the device. This malware can then be used to obtain sensitive information or further compromise DoD information systems. Restricting IM traff
    SV-50553r1_rule PB21-00-000310 CCI-001159 HIGH Only DoD PKI issued or DoD approved software authentication certificates may be installed on BlackBerry PlayBook OS. If unauthorized software authentication certificates are installed on the device, then the operating system would not block malware signed by the entity that published these certificates. Such malware could be used to obtain sensitive DoD information or t
    SV-50554r1_rule PB21-00-000320 CCI-001159 MEDIUM Only DoD PKI issued or DoD approved server authentication certificates may be installed on BlackBerry PlayBook OS. If unauthorized device authentication certificates are installed on the device, there is the potential that the device may connect to a rogue device or network. Rogue devices can mimic the behavior of authorized equipment to trick the user into providing
    SV-50555r1_rule PB21-00-000330 CCI-001265 MEDIUM BlackBerry PlayBook OS must prevent a user from using a browser that does not direct its traffic to a DoD proxy server. Proxy servers can inspect traffic for malware and other signs of a security attack. Allowing a mobile device to access the public Internet without proxy server inspection forgoes the protection that the proxy server would otherwise provide. Malware downlo
    SV-50557r1_rule PB21-00-000350 CCI-000370 MEDIUM BlackBerry PlayBook OS must employ mobile device management services to centrally manage IT Policies Security related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not implemented, the system may be vulnerable to a variety of atta
    SV-50558r1_rule PB21-00-000360 CCI-000370 MEDIUM BlackBerry PlayBook OS must employ mobile device management services to centrally manage email settings Security related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not implemented, the system may be vulnerable to a variety of atta
    SV-50559r1_rule PB21-00-000370 CCI-000370 MEDIUM BlackBerry PlayBook OS must employ mobile device management services to centrally manage Wi-Fi profiles Security related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not implemented, the system may be vulnerable to a variety of atta
    SV-50560r1_rule PB21-00-000380 CCI-000370 MEDIUM BlackBerry PlayBook OS must employ mobile device management services to centrally manage VPN profiles Security related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not implemented, the system may be vulnerable to a variety of atta
    SV-50561r1_rule PB21-00-000390 CCI-001200 MEDIUM BlackBerry PlayBook OS must encrypt all data on the mobile device using AES encryption (AES 128 bit encryption key length is the minimum requirement; AES 256 desired). If data at rest is unencrypted, it is vulnerable to disclosure. Even if the operating system enforces permissions on data access, an adversary can remove non-volatile memory and read it directly, thereby circumventing operating system controls. Encrypting
    SV-50562r1_rule PB21-00-000400 CCI-000066 MEDIUM BlackBerry PlayBook OS must prohibit wireless remote access connections except for personal hotspot service. The device acts as a personal hotspot when it accepts remote connections on a local area network interface for the purposes of routing traffic to a wide area network interface. The most common implementation is to accept local area Wi-Fi connections to re
    SV-50563r1_rule PB21-00-000410 CCI-000366 MEDIUM BlackBerry PlayBook OS must not permit a user to disable the password-protected lock feature on the work space. If the user is able to disable the password-protected lock feature, the user can change the configuration of the device to allow access without a password. The modified configuration would enable an adversary with access to the device to obtain DoD inform
    SV-50564r1_rule PB21-00-000420 CCI-000366 MEDIUM BlackBerry PlayBook OS must allow user to configure a non-complex 4 digit password for the personal space. If the user is able to disable the password-protected lock feature, the user can change the configuration of the device to allow access without a password. The modified configuration would enable an adversary with access to the device to obtain DoD inform
    SV-68129r1_rule PB21-00-000000 CCI-000366 HIGH BlackBerry PlayBook OS versions no longer supported by the manufacturer or vendor must not be installed on a device. Unsupported versions of the operating system do not contain new security-related features and security patches that address known vulnerabilities. Software or hardware no longer supported by the manufacturer or vendor are not maintained or updated for cur