BlackBerry 10.2.x OS Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- BB10-2X-000100
- Vuln IDs
-
- V-47169
- Rule IDs
-
- SV-60041r2_rule
Checks: C-49995r1_chk
From either the Work Space or Personal Space, while holding the Power button, select "Lock" to lock the device. Ensure "I've read & consent to terms in IS user agreem't." is displayed on the lock screen. Otherwise, this is a finding.
Fix: F-50873r1_fix
On BlackBerry Device Service server, set "Owner Information" IT Policy rule to "I've read & consent to terms in IS user agreem't." NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- BB10-2X-000110
- Vuln IDs
-
- V-47171
- Rule IDs
-
- SV-60043r1_rule
Checks: C-49997r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance" and ensure "Work Password" is set to "On" and grayed out. Otherwise, this is a finding.
Fix: F-50875r1_fix
On BlackBerry Device Service, set "Password Required for Work Space" IT Policy rule to "Yes".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- BB10-2X-000120
- Vuln IDs
-
- V-47173
- Rule IDs
-
- SV-60045r1_rule
Checks: C-49999r2_chk
This requirement must meet one of the options below: Option 1: From either the Work Space or Personal Space, navigate to "Settings -> Security and Privacy -> Device Password" and ensure "Device Password" is set to "On". Otherwise, this is a finding. Option 2: From either the Work Space or Personal Space, navigate to "Settings > BlackBerry Balance" and ensure "Use as my device password" is set to "On" and greyed out. Otherwise, this is a finding.
Fix: F-50877r2_fix
Select one option to fix this requirement: Option 1: From either the Work Space or Personal Space, navigate to "Settings -> Security and Privacy -> Device Password" and set "Enable Device Password" to "On". Create a 4-digit password for device lock. Option 2: On BlackBerry Device Service, set "Apply Work Space Password to Full Device" rule to "Yes". NOTE: This fix procedure affects the Personal Space.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- BB10-2X-000130
- Vuln IDs
-
- V-47175
- Rule IDs
-
- SV-60047r1_rule
Checks: C-50001r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance". Ensure "Lock Work Space After" is set to "15 Minutes", with higher values hidden. Otherwise, this is a finding.
Fix: F-50879r1_fix
On BlackBerry Device Service, set "Lock Device After" IT Policy rule to "15 minutes".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- BB10-2X-000140
- Vuln IDs
-
- V-47177
- Rule IDs
-
- SV-60049r1_rule
Checks: C-50003r1_chk
On BlackBerry Device Service, verify "Application Security Timer Reset" IT Policy rule is set to "Disallow". Otherwise, this is a finding.
Fix: F-50881r1_fix
On BlackBerry Device Service, set "Application Security Timer Reset" IT Policy rule to "Disallow".
- RMF Control
- AU-8
- Severity
- L
- CCI
- CCI-000160
- Version
- BB10-2X-000150
- Vuln IDs
-
- V-47179
- Rule IDs
-
- SV-60051r1_rule
Checks: C-50005r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Date and Time" and ensure "Set Date and Time Automatically" is set to "On". Otherwise, this is a finding.
Fix: F-50883r1_fix
From either the Work Space or Personal Space, navigate to "Settings -> Date and Time" and set "Set Date and Time Automatically" to "On". NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- BB10-2X-000210
- Vuln IDs
-
- V-47181
- Rule IDs
-
- SV-60053r1_rule
Checks: C-50007r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance" and select "Change Password". Authenticate using the current password. Select "Password Rules" and ensure "Your password must be at least 6 characters." Otherwise, this is a finding.
Fix: F-50885r1_fix
On BlackBerry Device Service, set "Minimum Password Length" IT Policy rule to 6.
- RMF Control
- SA-7
- Severity
- H
- CCI
- CCI-000663
- Version
- BB10-2X-000220
- Vuln IDs
-
- V-47183
- Rule IDs
-
- SV-60055r2_rule
Checks: C-50009r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Security and Privacy -> Development Mode" and ensure "Use Development Mode" is set to "OFF" and grayed out. Otherwise, this is a finding.
Fix: F-50887r1_fix
On BlackBerry Device Service, set "Restrict Development Mode" IT Policy rule to "Yes".
- RMF Control
- SA-7
- Severity
- H
- CCI
- CCI-000663
- Version
- BB10-2X-000224
- Vuln IDs
-
- V-47185
- Rule IDs
-
- SV-60057r2_rule
Checks: C-50011r2_chk
If requirement BB10-2X-000220 is met, this requirement is not applicable. On BlackBerry Device Service, verify "Development Mode Access to Work Space" IT Policy rule is set to "Disallow". Otherwise, this is a finding.
Fix: F-50889r1_fix
On BlackBerry Device Service, set "Development Mode Access to Work Space" IT Policy rule to "Disallow".
- RMF Control
- SA-7
- Severity
- H
- CCI
- CCI-000663
- Version
- BB10-2X-000228
- Vuln IDs
-
- V-47187
- Rule IDs
-
- SV-60059r2_rule
Checks: C-50013r1_chk
On BlackBerry Device Service, verify "Install Apps From Other Sources" IT Policy rule is set to "Disallow". Otherwise, this is a finding.
Fix: F-50891r1_fix
On BlackBerry Device Service, set "Install Apps From Other Sources" IT Policy rule to "Disallow".
- RMF Control
- SA-7
- Severity
- M
- CCI
- CCI-000663
- Version
- BB10-2X-000230
- Vuln IDs
-
- V-47189
- Rule IDs
-
- SV-60061r1_rule
Checks: C-50015r1_chk
From the Work Space, open "BlackBerry World - Work" and select "Public". If any apps are listed under "Public", this is a finding.
Fix: F-50893r1_fix
On BlackBerry Device Service, on the BlackBerry solution management menu, expand "Software -> Applications", click "Manage applications", and delete all applications under "BlackBerry World Applications".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000780
- Version
- BB10-2X-000240
- Vuln IDs
-
- V-47191
- Rule IDs
-
- SV-60063r1_rule
Checks: C-50017r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> Wi-Fi -> Saved" and select a saved DoD Wi-Fi profile to check. Ensure "Security Type" is set to "WPA Enterprise" or "WPA2 Enterprise" and "Security Sub Type" is set to "EAP-TLS". These options should be grayed out. Otherwise, this is a finding. NOTE: Wi-Fi profiles, other than those connecting to DoD Wi-Fi networks, are not a finding. If no DoD Wi-Fi networks are saved, this requirement is NA.
Fix: F-50895r2_fix
On BlackBerry Device Service, select the affected Wi-Fi Profile(s), and set "EAP Security Setting" to "TLS".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000780
- Version
- BB10-2X-000250
- Vuln IDs
-
- V-47193
- Rule IDs
-
- SV-60065r1_rule
Checks: C-50019r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN ". Select and hold a VPN profile to check, and select "Edit Profile" to edit the VPN Profile. For each VPN Profile connecting to DoD networks: - Select the VPN Profile to edit. - Ensure "Authentication Type" is set to "PKI" or "XAUTH-PKI" and grayed out. Otherwise, this is a finding. NOTE: If the VPN Profile listed under "Settings -> Network Connections -> VPN" has a brief case logo on the right side, it is created on BlackBerry Device Service published to the device. "Authentication Type" for this VPN Profile will be grayed out and enforced. If no VPN profiles are saved, this requirement is NA.
Fix: F-50897r1_fix
On BlackBerry Device Service, set select the applicable VPN Profile and set "Authentication Type" is to "PKI" or "XAUTH-PKI".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- BB10-2X-000280
- Vuln IDs
-
- V-47197
- Rule IDs
-
- SV-60069r2_rule
Checks: C-50023r1_chk
From the Work Space, navigate to "Settings -> Security and Privacy -> Certificates", and inspect "Enterprise Root Certificates" and "Enterprise Intermediate Certificates" stores. If DoD root and intermediate PKI certificates are not in the stores, this is a finding.
Fix: F-50901r2_fix
On BlackBerry Device Service, ensure the required ".pem" files are present in <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www> folder.
- RMF Control
- SC-15
- Severity
- M
- CCI
- CCI-001154
- Version
- BB10-2X-000290
- Vuln IDs
-
- V-47199
- Rule IDs
-
- SV-60071r2_rule
Checks: C-50025r1_chk
On BlackBerry Device Service: In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications -> Manage applications". If there are any unauthorized instant messaging systems listed, this is a finding.
Fix: F-50903r1_fix
On BlackBerry Device Service: In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications -> Manage applications". Delete the unauthorized IM system application.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- BB10-2X-000300
- Vuln IDs
-
- V-47201
- Rule IDs
-
- SV-60073r1_rule
Checks: C-50027r2_chk
From the Work Space, navigate to "Settings -> Security and Privacy -> Application Permissions" and select "All" in the "Permissions" dropdown box. For each application, ensure the requested permissions (e.g., Location, Contacts, Shared Files, etc.) are set to "On" only for AO authorized permissions. Otherwise, this is a finding. NOTE: If no applications are installed, this requirement is NA.
Fix: F-50905r2_fix
From the Work Space, navigate to "Settings -> Security and Privacy -> Application Permissions" and select "All" in "Permissions" dropdown box. For each application, set requested permission (e.g. Location, Contacts, Shared Files, etc.) to "On" or "Off" identified by the AO. NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- SC-17
- Severity
- H
- CCI
- CCI-001159
- Version
- BB10-2X-000310
- Vuln IDs
-
- V-47203
- Rule IDs
-
- SV-60075r1_rule
Checks: C-50029r1_chk
From the Work Space, navigate to "Settings -> Security and Privacy -> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"). Ensure the certificates listed originated from the BDS server. Certificates not originating from a DoD BDS server are a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply.
Fix: F-50907r1_fix
On BlackBerry Device Service, remove the corresponding .pem file from <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www> folder.
- RMF Control
- SC-17
- Severity
- M
- CCI
- CCI-001159
- Version
- BB10-2X-000320
- Vuln IDs
-
- V-47205
- Rule IDs
-
- SV-60077r1_rule
Checks: C-50031r1_chk
From the Work Space, navigate to "Settings -> Security and Privacy -> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"). Ensure the certificates listed originated from the BDS server. Certificates not originating from a DoD BDS server are a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply.
Fix: F-50909r1_fix
On BlackBerry Device Service, remove the corresponding .pem file from <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www> folder.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-001237
- Version
- BB10-2X-000325
- Vuln IDs
-
- V-47207
- Rule IDs
-
- SV-60079r1_rule
Checks: C-50033r2_chk
From either the Work Space or Personal Space, navigate to "Settings -> About" and ensure "Software Release" indicates version 10.2.1.1898, or higher. Otherwise, this is a finding.
Fix: F-50911r2_fix
From either the Work Space or Personal Space, navigate to "Settings -> Software Updates" and select "Check for Updates". NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-001265
- Version
- BB10-2X-000330
- Vuln IDs
-
- V-47209
- Rule IDs
-
- SV-60081r1_rule
Checks: C-50035r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> Wi-Fi -> Saved Networks". For each saved network, ensure "Use HTTP Proxy" is set to "On" and grayed out with appropriate proxy information filled out (such as: "Proxy Server", "Proxy Port", "Username", "Password"). If "Use HTTP Proxy" is set to "Off", this is a finding. NOTE: Proxy server information can be configured on the Wi-Fi profile. When configured, all traffic, including browser traffic, will flow through the configured proxy server.
Fix: F-50913r1_fix
On BlackBerry Device Service, open the affected Wi-Fi Profile for edit, and set "Associated Proxy Profile" to the preconfigured Proxy Profile for DoD use.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-001265
- Version
- BB10-2X-000335
- Vuln IDs
-
- V-47211
- Rule IDs
-
- SV-60083r1_rule
Checks: C-50037r1_chk
On BlackBerry Device Service, navigate to the Servers and components menu and expand BlackBerry Solution topology >> BlackBerry Domain >> Component view >> BlackBerry Device Service. Click the name of the BlackBerry Device Service instance. Verify in the Instance associations pane, the preconfigured Proxy Profile for DoD use is shown as the value for the Proxy profile. If the preconfigured Proxy Profile for DoD use is not shown for the value for the Proxy profile, this is a finding.
Fix: F-50915r1_fix
On BlackBerry Device Service, navigate to the Servers and components menu and expand BlackBerry Solution topology >> BlackBerry Domain >> Component view >> BlackBerry Device Service. Click the name of the BlackBerry Device Service instance and click Edit instance. In the Instance associations section, in the Proxy profile drop-down list, select the preconfigured Proxy Profile for DoD use. Click Save all.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-001265
- Version
- BB10-2X-000340
- Vuln IDs
-
- V-47213
- Rule IDs
-
- SV-60085r1_rule
Checks: C-50039r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN -> Edit". For each VPN profile, expand the configuration to "Advanced" and ensure the "Use Proxy" checkbox is checked and grayed out, with appropriate proxy information filled out (such as: "Proxy Server", "Proxy Port", "Username", "Password"). If the "Use Proxy" checkbox is unchecked, this is a finding. NOTE: Proxy server information can be configured on the VPN profile. When configured, all traffic, including browser traffic, will flow through the configured proxy server.
Fix: F-50917r1_fix
On BlackBerry Device Service, open the affected VPN Profile for edit, and set "Associated Proxy Profile" to the preconfigured Proxy Profile for DoD use.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- BB10-2X-000350
- Vuln IDs
-
- V-47215
- Rule IDs
-
- SV-60087r1_rule
Checks: C-50041r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance. Under "Work Password", ensure the maximum value in the "Password attempt limit" drop down box is not greater than 10 (or organization defined number). Otherwise, this is a finding.
Fix: F-50919r1_fix
On BlackBerry Device Service, set "Maximum Password Attempts" IT Policy rule to 10 (or the organization defined value).
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- BB10-2X-000360
- Vuln IDs
-
- V-47217
- Rule IDs
-
- SV-60089r1_rule
Checks: C-50043r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> About -> Work Space". Under "IT Policy", verify "Policy Name" value is identical to the name of the IT Policy assigned from BDS. Otherwise, this is a finding.
Fix: F-50921r2_fix
On BlackBerry Device Service, navigate to "BlackBerry solution management -> User -> Manage users -> <affected user's device PIN>". Select "Resend IT Policy to a device".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- BB10-2X-000370
- Vuln IDs
-
- V-47219
- Rule IDs
-
- SV-60091r1_rule
Checks: C-50045r2_chk
From the Work Space, navigate to "Settings -> Accounts". Verify all required work email accounts (with a briefcase icon) are present. Otherwise, this is a finding.
Fix: F-50923r2_fix
On BlackBerry Device Service, navigate to "BlackBerry solution management -> Profiles -> Manage email profiles". Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create email profiles". Assign all required email profiles to affected user, or a group the user is a part of.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- BB10-2X-000380
- Vuln IDs
-
- V-47221
- Rule IDs
-
- SV-60093r1_rule
Checks: C-50047r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> Wi-Fi -> Saved". Verify all required work Wi-Fi profiles (with a briefcase icon) are present. Otherwise, this is a finding. NOTE: Additional profiles without the briefcase icon are permitted and are not a finding.
Fix: F-50925r2_fix
On BlackBerry Device Service, navigate to "BlackBerry solution management -> Profiles -> Manage Wi-Fi Profiles". Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create Wi-Fi Profiles". Assign all required Wi-Fi profiles to affected user, or a group the user is a part of.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- BB10-2X-000390
- Vuln IDs
-
- V-47223
- Rule IDs
-
- SV-60095r1_rule
Checks: C-50049r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN". Verify all required work VPN profiles (with a briefcase icon) are present. Otherwise, this is a finding.
Fix: F-50927r2_fix
On BlackBerry Device Service, navigate to "BlackBerry solution management -> Profiles -> Manage VPN Profiles". Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create VPN Profiles". Assign all required VPN profiles to affected user, or a group the user is a part of.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000066
- Version
- BB10-2X-000410
- Vuln IDs
-
- V-47225
- Rule IDs
-
- SV-60097r1_rule
Checks: C-50051r1_chk
On BlackBerry Device Service, verify "Computer Access to Device" IT Policy rule is set to "Disallow". Otherwise, this is a finding.
Fix: F-50929r1_fix
On BlackBerry Device Service, set "Computer Access to Device" IT Policy rule to "Disallow".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000066
- Version
- BB10-2X-000420
- Vuln IDs
-
- V-47227
- Rule IDs
-
- SV-60099r1_rule
Checks: C-50053r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Media Sharing" and ensure all of "Share Music", "Share Pictures", and "Share Videos" are set to "Off". Otherwise, this is a finding.
Fix: F-50931r1_fix
From the Work Space, navigate to "Settings -> Media Sharing" and set all of "Share Music", "Share Pictures" and "Share Videos" to "Off". NOTE: This fix procedure affects the Personal Space.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- BB10-2X-000430
- Vuln IDs
-
- V-47229
- Rule IDs
-
- SV-60101r1_rule
Checks: C-50055r1_chk
On BlackBerry Device Service: Ensure "Personal Apps Access to Work Contacts" IT Policy rule is set to "Only BlackBerry Apps". Otherwise, this is a finding.
Fix: F-50933r1_fix
On BlackBerry Device Service, set "Personal Apps Access to Work Contacts" IT Policy rule to "Only BlackBerry Apps". NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000060
- Version
- BB10-2X-002140
- Vuln IDs
-
- V-47231
- Rule IDs
-
- SV-60103r1_rule
Checks: C-50057r1_chk
While holding the Power button from either the Work Space or Personal Space, select "Lock" to lock the device. Ensure the Work Space content is not visible on the lock screen. Otherwise, this is a finding.
Fix: F-50935r1_fix
On BlackBerry Device Service, set "Lock Screen Preview of Work Content" to "Disallow".
- RMF Control
- IA-5
- Severity
- L
- CCI
- CCI-000185
- Version
- BB10-2X-002160
- Vuln IDs
-
- V-47233
- Rule IDs
-
- SV-60105r1_rule
Checks: C-50059r1_chk
On BlackBerry Device Service, navigate to "Devices -> Device settings -> Certificate retrieval settings -> Edit Settings -> OCSP" and verify "Service URL" field is populated with the correct value. Otherwise, this is a finding.
Fix: F-50937r1_fix
On BlackBerry Device Service, navigate to "Devices -> Device settings -> Certificate retrieval settings -> Edit Settings -> OCSP" and set "Service URL" field to appropriate URL of the OCSP server.
- RMF Control
- SC-4
- Severity
- L
- CCI
- CCI-001090
- Version
- BB10-2X-003360
- Vuln IDs
-
- V-47237
- Rule IDs
-
- SV-60109r1_rule
Checks: C-50063r1_chk
On BlackBerry Device Service, verify "Work App Access to Shared Files in the Personal Space" IT Policy rule is set to "Disallow". Otherwise, this is a finding.
Fix: F-50941r1_fix
On BlackBerry Device Service, set "Work App Access to Shared Files in the Personal Space" IT Policy rule to "Disallow".
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001130
- Version
- BB10-2X-000270
- Vuln IDs
-
- V-48597
- Rule IDs
-
- SV-61473r1_rule
Checks: C-50923r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN". Select "Edit" to edit a VPN Profile. For each VPN Profile connecting to DoD networks: - Select the VPN Profile to edit. - Ensure "Gateway Type" is set to a type which supports and utilizes IPsec and SSL/TLS. Otherwise, this is a finding. NOTE: If no VPN profiles are saved, this requirement is NA.
Fix: F-52203r1_fix
On BlackBerry Device Service, select the affected VPN Profile for edit, and set "Gateway Type" to a type which supports and utilizes IPsec and SSL/TLS.