BlackBerry 10.2.x OS Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates −6 ⚠ 2 ✎ 23
Comparison against the immediately-prior release (V1R3). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Removed rules 6
- V-47209 Medium BlackBerry 10 OS must prevent a user from using a browser that does not direct its traffic to a DoD proxy server.
- V-47211 Medium BlackBerry 10 OS must use a DoD proxy server.
- V-47213 Medium BlackBerry 10 OS must prevent a user from using a browser that does not direct its traffic to a DoD proxy server.
- V-47225 Medium BlackBerry 10 OS must prohibit wireless remote access connection for storage.
- V-47227 Medium BlackBerry 10 OS must prohibit wireless remote access connection for media sharing.
- V-47237 Low BlackBerry 10 OS must prevent DoD applications from accessing non-DoD data when the device supports multiple user environments (e.g., work and personal) if such access has not been approved.
Severity changes 2
Content changes 23
- V-47171 Medium check BlackBerry 10 OS must retain the lock on the Work Space until the user reestablishes access using established identification and authentication procedures.
- V-47173 Medium checkfix BlackBerry 10 OS must retain the device lock until the user reestablishes access using established identification and authentication procedures.
- V-47175 Medium checkfix BlackBerry 10 OS must lock the Work Space after no more than 15 minutes of inactivity.
- V-47177 Medium checkfix BlackBerry 10 OS must prevent applications from extending the Work Space password lock time.
- V-47179 Low checkfix BlackBerry 10 OS must synchronize the internal clock on an organizationally-defined periodic basis with an authoritative time server or the Global Positioning System.
- V-47181 Medium checkfix BlackBerry 10 OS must enforce a minimum length for the Work Space unlock password.
- V-47185 High descriptioncheckfix BlackBerry 10 OS must prevent a user from installing unapproved applications in the Work Space.
- V-47189 Medium descriptionfix BlackBerry 10 OS must only permit downloading of software from a DoD-approved source (e.g., DoD-operated mobile device application store or MDM server).
- V-47191 Medium check BlackBerry 10 OSs Wi-Fi module must use EAP-TLS authentication when authenticating to DoD WLAN authentication servers.
- V-47193 Medium descriptioncheckfix BlackBerry 10 OS VPN client must employ DoD PKI-approved mechanisms for authentication when connecting to DoD networks.
- V-47197 Medium checkfix BlackBerry 10 OS must have access to DoD root and intermediate PKI certificates when performing DoD PKI-related transactions.
- V-47199 Medium descriptioncheckfix BlackBerry 10 OS must block both the inbound and outbound traffic between instant messaging clients that are independently configured by end users and external service providers or other unapproved DoD systems.
- V-47201 High checkfix BlackBerry 10 OS must grant a downloaded application only the permissions the AO has authorized for that application.
- V-47203 High checkfix The BlackBerry 10 OS Work Space must only install and use DoD PKI-issued or DoD-approved software authentication certificates.
- V-47205 Medium checkfix The BlackBerry 10 OS Work Space must only install and use DoD PKI-issued or DoD-approved server authentication certificates.
- V-47207 Medium descriptioncheckfix BlackBerry 10 OS must be updated to the latest approved version of the operating system.
- V-47215 Medium checkfix BlackBerry 10 OS maximum number of consecutive unsuccessful unlock attempts must be less than 10.
- V-47217 Medium checkfix BlackBerry 10 OS must employ mobile device management services to centrally manage IT Policies.
- V-47219 Medium checkfix BlackBerry 10 OS must employ mobile device management services to centrally manage email settings.
- V-47221 Medium checkfix BlackBerry 10 OS must employ mobile device management services to centrally manage Wi-Fi profiles.
- V-47229 Low checkfix BlackBerry 10 OS must enable a system administrator to (i) select which data fields will be available to applications outside of the contact database application and (ii) limit the number of contact database fields accessible outside of a work persona in the case of dual persona phones.
- V-47233 Low checkfix BlackBerry 10 OS, for PKI-based authentication must validate certificates by querying the certification authority for revocation status of the certificate.
- V-48597 Medium check BlackBerry 10 OSs VPN client must use either IPsec or SSL/TLS when connecting to DoD networks.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- BB10-2X-000100
- Vuln IDs
-
- V-47169
- Rule IDs
-
- SV-60041r3_rule
Checks: C-49995r2_chk
From either the Work Space or Personal Space, while holding the Power button, select "Lock" to lock the device. Ensure " I've read & consent to terms in IS user agreem't." is displayed on the lock screen. Otherwise, this is a finding.
Fix: F-50873r2_fix
On BlackBerry Device Service server, set "Owner Information" IT Policy rule to " I've read & consent to terms in IS user agreem't." NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- BB10-2X-000110
- Vuln IDs
-
- V-47171
- Rule IDs
-
- SV-60043r2_rule
Checks: C-49997r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance" and ensure "Work Password" is set to "On" and grayed out. Otherwise, this is a finding.
Fix: F-50875r1_fix
On BlackBerry Device Service, set "Password Required for Work Space" IT Policy rule to "Yes".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- BB10-2X-000120
- Vuln IDs
-
- V-47173
- Rule IDs
-
- SV-60045r2_rule
Checks: C-49999r3_chk
This requirement must meet one of the options below: Option 1: From either the Work Space or Personal Space, navigate to "Settings >> Security and Privacy >> Device Password" and ensure "Device Password" is set to "On". Otherwise, this is a finding. Option 2: From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance" and ensure "Use as my device password" is set to "On" and greyed out. Otherwise, this is a finding.
Fix: F-50877r3_fix
Select one option to fix this requirement: Option 1: From either the Work Space or Personal Space, navigate to "Settings >> Security and Privacy >> Device Password" and set "Enable Device Password" to "On". Create a 4-digit password for device lock. Option 2: On BlackBerry Device Service, set "Apply Work Space Password to Full Device" rule to "Yes". Note: This fix procedure affects the Personal Space.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- BB10-2X-000130
- Vuln IDs
-
- V-47175
- Rule IDs
-
- SV-60047r3_rule
Checks: C-50001r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance". Verify "Lock Work Space After" is set to "15 Minutes", with higher values hidden. Otherwise, this is a finding.
Fix: F-50879r2_fix
On BlackBerry Device Service, set the IT Policy rule "Lock Device After" to "15 minutes".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- BB10-2X-000140
- Vuln IDs
-
- V-47177
- Rule IDs
-
- SV-60049r3_rule
Checks: C-50003r2_chk
On BlackBerry Device Service, verify the IT Policy rule "Application Security Timer Reset" is set to "Disallow". Otherwise, this is a finding.
Fix: F-50881r2_fix
On BlackBerry Device Service, set the IT Policy rule "Application Security Timer Reset" to "Disallow".
- RMF Control
- AU-8
- Severity
- L
- CCI
- CCI-000160
- Version
- BB10-2X-000150
- Vuln IDs
-
- V-47179
- Rule IDs
-
- SV-60051r2_rule
Checks: C-50005r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> Date and Time" and verify "Set Date and Time Automatically" is set to "On". Otherwise, this is a finding.
Fix: F-50883r2_fix
From either the Work Space or Personal Space, navigate to "Settings >> Date and Time" and set "Set Date and Time Automatically" to "On". NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- BB10-2X-000210
- Vuln IDs
-
- V-47181
- Rule IDs
-
- SV-60053r3_rule
Checks: C-50007r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance" and select "Change Password". Authenticate using the current password. Select "Password Rules" and verify "Your password must be at least 6 characters." Otherwise, this is a finding.
Fix: F-50885r2_fix
On BlackBerry Device Service, set the IT Policy rule "Minimum Password Length" to 6.
- RMF Control
- SA-7
- Severity
- M
- CCI
- CCI-000663
- Version
- BB10-2X-000220
- Vuln IDs
-
- V-47183
- Rule IDs
-
- SV-60055r5_rule
Checks: C-50009r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> Security and Privacy >> Development Mode" and verify "Use Development Mode" is set to "OFF" and grayed out. Otherwise, this is a finding.
Fix: F-50887r3_fix
On BlackBerry Device Service, set the IT Policy rule "Restrict Development Mode" to "Yes".
- RMF Control
- SA-7
- Severity
- H
- CCI
- CCI-000663
- Version
- BB10-2X-000224
- Vuln IDs
-
- V-47185
- Rule IDs
-
- SV-60057r3_rule
Checks: C-50011r4_chk
If requirement BB10-2X-000220 is met, this requirement is not applicable. On BlackBerry Device Service, verify the IT Policy rule "Development Mode Access to Work Space" is set to "Disallow". Otherwise, this is a finding.
Fix: F-50889r2_fix
On BlackBerry Device Service, set the IT Policy rule "Development Mode Access to Work Space" to "Disallow".
- RMF Control
- SA-7
- Severity
- M
- CCI
- CCI-000663
- Version
- BB10-2X-000228
- Vuln IDs
-
- V-47187
- Rule IDs
-
- SV-60059r4_rule
Checks: C-50013r3_chk
On BlackBerry Device Service, verify the IT Policy rule "Install Apps From Other Sources" is set to "Disallow". Otherwise, this is a finding.
Fix: F-50891r3_fix
On BlackBerry Device Service, set the IT Policy rule "Install Apps From Other Sources" to "Disallow".
- RMF Control
- SA-7
- Severity
- M
- CCI
- CCI-000663
- Version
- BB10-2X-000230
- Vuln IDs
-
- V-47189
- Rule IDs
-
- SV-60061r3_rule
Checks: C-50015r1_chk
From the Work Space, open "BlackBerry World - Work" and select "Public". If any apps are listed under "Public", this is a finding.
Fix: F-50893r2_fix
On BlackBerry Device Service, on the BlackBerry solution management menu, expand "Software >> Applications", click "Manage applications", and delete all applications under "BlackBerry World Applications".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000780
- Version
- BB10-2X-000240
- Vuln IDs
-
- V-47191
- Rule IDs
-
- SV-60063r2_rule
Checks: C-50017r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> Network Connections >> Wi-Fi >> Saved" and select a saved DoD Wi-Fi profile to check. Verify "Security Type" is set to "WPA Enterprise" or "WPA2 Enterprise" and "Security Sub Type" is set to "EAP-TLS". These options should be grayed out. Otherwise, this is a finding. NOTE: Wi-Fi profiles, other than those connecting to DoD Wi-Fi networks, are not a finding. If no DoD Wi-Fi networks are saved, this requirement is NA.
Fix: F-50895r2_fix
On BlackBerry Device Service, select the affected Wi-Fi Profile(s), and set "EAP Security Setting" to "TLS".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000780
- Version
- BB10-2X-000250
- Vuln IDs
-
- V-47193
- Rule IDs
-
- SV-60065r3_rule
Checks: C-50019r4_chk
From either the Work Space or Personal Space, navigate to "Settings >> Network Connections >> VPN ". Select and hold a VPN profile to check, and select "Edit Profile" to edit the VPN Profile. For each VPN Profile connecting to DoD networks: - Select the VPN Profile to edit. - Verify "Authentication Type" is set to "PKI" or "XAUTH-PKI" and grayed out. Otherwise, this is a finding. NOTE: If the VPN Profile listed under "Settings >> Network Connections >> VPN" has a brief case logo on the right side, it was created on BlackBerry Device Service published to the device. "Authentication Type" for this VPN Profile will be grayed out and enforced. If no VPN profiles are saved, this requirement is NA.
Fix: F-50897r3_fix
On BlackBerry Device Service, select the applicable VPN Profile and set "Authentication Type" to "PKI" or "XAUTH-PKI".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- BB10-2X-000280
- Vuln IDs
-
- V-47197
- Rule IDs
-
- SV-60069r4_rule
Checks: C-50023r3_chk
From the Work Space, navigate to "Settings >> Security and Privacy >> Certificates", and inspect "Enterprise Root Certificates" and "Enterprise Intermediate Certificates" stores. If DoD root and intermediate PKI certificates are not in the stores, this is a finding.
Fix: F-50901r3_fix
On BlackBerry Device Service, ensure the required ".pem" files are present in this folder: <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www>
- RMF Control
- SC-15
- Severity
- M
- CCI
- CCI-001154
- Version
- BB10-2X-000290
- Vuln IDs
-
- V-47199
- Rule IDs
-
- SV-60071r4_rule
Checks: C-50025r3_chk
On BlackBerry Device Service, in the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software >> Applications >> Manage applications". If there are any unauthorized instant messaging systems listed, this is a finding.
Fix: F-50903r2_fix
On BlackBerry Device Service: In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software >> Applications >> Manage applications". Delete the unauthorized IM system application.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- BB10-2X-000300
- Vuln IDs
-
- V-47201
- Rule IDs
-
- SV-60073r3_rule
Checks: C-50027r3_chk
From the Work Space, navigate to "Settings >> Security and Privacy >> Application Permissions" and select "All" in the "Permissions" dropdown box. For each application, ensure the requested permissions (e.g., Location, Contacts, Shared Files, etc.) are set to "On" only for AO authorized permissions. Otherwise, this is a finding. NOTE: If no applications are installed, this requirement is NA.
Fix: F-50905r5_fix
From the Work Space, navigate to "Settings >> Security and Privacy >> Application Permissions" and select "All" in "Permissions" dropdown box. For each application, set requested permission (e.g. Location, Contacts, Shared Files, etc.) to "On" or "Off" as identified by the AO.
- RMF Control
- SC-17
- Severity
- H
- CCI
- CCI-001159
- Version
- BB10-2X-000310
- Vuln IDs
-
- V-47203
- Rule IDs
-
- SV-60075r3_rule
Checks: C-50029r3_chk
From the Work Space, navigate to "Settings >> Security and Privacy >> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"). Verify the certificates listed originated from the BDS server. If the certificates do not originate from a DoD BDS server, this is a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply.
Fix: F-50907r2_fix
On BlackBerry Device Service, remove the corresponding .pem file from this folder: <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www>
- RMF Control
- SC-17
- Severity
- M
- CCI
- CCI-001159
- Version
- BB10-2X-000320
- Vuln IDs
-
- V-47205
- Rule IDs
-
- SV-60077r3_rule
Checks: C-50031r3_chk
From the Work Space, navigate to "Settings >> Security and Privacy >> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"). Verify the certificates listed originated from the BDS server. If the certificates do not originate from a DoD BDS server, this is a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply.
Fix: F-50909r2_fix
On BlackBerry Device Service, remove the corresponding .pem file from this folder: <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www>
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-001237
- Version
- BB10-2X-000325
- Vuln IDs
-
- V-47207
- Rule IDs
-
- SV-60079r2_rule
Checks: C-50033r3_chk
From either the Work Space or Personal Space, navigate to "Settings >> About" and verify "Software Release" indicates version 10.2.1.1925, or higher. Otherwise, this is a finding.
Fix: F-50911r3_fix
From either the Work Space or Personal Space, navigate to "Settings >> Software Updates" and select "Check for Updates". NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- BB10-2X-000350
- Vuln IDs
-
- V-47215
- Rule IDs
-
- SV-60087r2_rule
Checks: C-50041r3_chk
From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance”. Under "Work Password", ensure the maximum value in the "Password attempt limit" drop down box is less than 10, otherwise, this is a finding.
Fix: F-50919r2_fix
On BlackBerry Device Service, set the IT Policy rule "Maximum Password Attempts" to be less than 10.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- BB10-2X-000360
- Vuln IDs
-
- V-47217
- Rule IDs
-
- SV-60089r2_rule
Checks: C-50043r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> About >> Work Space". Under "IT Policy", verify "Policy Name" value is identical to the name of the IT Policy assigned from BDS. Otherwise, this is a finding.
Fix: F-50921r3_fix
On BlackBerry Device Service, navigate to "BlackBerry solution management >> User >> Manage users >> <affected user's device PIN>". Select "Resend IT Policy to a device".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- BB10-2X-000370
- Vuln IDs
-
- V-47219
- Rule IDs
-
- SV-60091r2_rule
Checks: C-50045r3_chk
From the Work Space, navigate to "Settings >> Accounts". Verify all required work email accounts (with a briefcase icon) are present. Otherwise, this is a finding.
Fix: F-50923r3_fix
On BlackBerry Device Service, navigate to "BlackBerry solution management >> Profiles >> Manage email profiles". Verify all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management >> Profiles >> Create email profiles". Assign all required email profiles to affected user, or a group the user is a part of.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- BB10-2X-000380
- Vuln IDs
-
- V-47221
- Rule IDs
-
- SV-60093r2_rule
Checks: C-50047r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> Network Connections >> Wi-Fi >> Saved". Verify all required work Wi-Fi profiles (with a briefcase icon) are present. Otherwise, this is a finding. NOTE: Additional profiles without the briefcase icon are permitted and are not a finding.
Fix: F-50925r3_fix
On BlackBerry Device Service, navigate to "BlackBerry solution management >> Profiles >> Manage Wi-Fi Profiles". Verify all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management >> Profiles >> Create Wi-Fi Profiles". Assign all required Wi-Fi profiles to affected user, or a group the user is a part of.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- BB10-2X-000390
- Vuln IDs
-
- V-47223
- Rule IDs
-
- SV-60095r2_rule
Checks: C-50049r1_chk
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN". Verify all required work VPN profiles (with a briefcase icon) are present. Otherwise, this is a finding.
Fix: F-50927r2_fix
On BlackBerry Device Service, navigate to "BlackBerry solution management -> Profiles -> Manage VPN Profiles". Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create VPN Profiles". Assign all required VPN profiles to affected user, or a group the user is a part of.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- BB10-2X-000430
- Vuln IDs
-
- V-47229
- Rule IDs
-
- SV-60101r2_rule
Checks: C-50055r2_chk
On BlackBerry Device Service: Ensure the IT Policy rule "Personal Apps Access to Work Contacts" is set to "Only BlackBerry Apps". Otherwise, this is a finding.
Fix: F-50933r2_fix
On BlackBerry Device Service, set the IT Policy rule "Personal Apps Access to Work Contacts" to "Only BlackBerry Apps". NOTE: This fix procedure affects both Personal and Work Spaces.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000060
- Version
- BB10-2X-002140
- Vuln IDs
-
- V-47231
- Rule IDs
-
- SV-60103r1_rule
Checks: C-50057r1_chk
While holding the Power button from either the Work Space or Personal Space, select "Lock" to lock the device. Ensure the Work Space content is not visible on the lock screen. Otherwise, this is a finding.
Fix: F-50935r1_fix
On BlackBerry Device Service, set "Lock Screen Preview of Work Content" to "Disallow".
- RMF Control
- IA-5
- Severity
- L
- CCI
- CCI-000185
- Version
- BB10-2X-002160
- Vuln IDs
-
- V-47233
- Rule IDs
-
- SV-60105r2_rule
Checks: C-50059r2_chk
On BlackBerry Device Service, navigate to "Devices >> Device settings >> Certificate retrieval settings >> Edit Settings >> OCSP" and verify "Service URL" field is populated with the correct value. Otherwise, this is a finding.
Fix: F-50937r2_fix
On BlackBerry Device Service, navigate to "Devices >> Device settings >> Certificate retrieval settings >> Edit Settings >> OCSP" and set "Service URL" field to appropriate URL of the OCSP server.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001130
- Version
- BB10-2X-000270
- Vuln IDs
-
- V-48597
- Rule IDs
-
- SV-61473r2_rule
Checks: C-50923r2_chk
From either the Work Space or Personal Space, navigate to "Settings >> Network Connections >> VPN". Select "Edit" to edit a VPN Profile. For each VPN Profile connecting to DoD networks: - Select the VPN Profile to edit. - Ensure "Gateway Type" is set to a type which supports and utilizes IPsec and SSL/TLS. Otherwise, this is a finding. NOTE: If no VPN profiles are saved, this requirement is NA.
Fix: F-52203r1_fix
On BlackBerry Device Service, select the affected VPN Profile for edit, and set "Gateway Type" to a type which supports and utilizes IPsec and SSL/TLS.