Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
From either the Work Space or Personal Space, while holding the Power button, select "Lock" to lock the device. Ensure " I've read & consent to terms in IS user agreem't." is displayed on the lock screen. Otherwise, this is a finding.
On BlackBerry Device Service server, set "Owner Information" IT Policy rule to " I've read & consent to terms in IS user agreem't." NOTE: This fix procedure affects both Personal and Work Spaces.
From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance" and ensure "Work Password" is set to "On" and grayed out. Otherwise, this is a finding.
On BlackBerry Device Service, set "Password Required for Work Space" IT Policy rule to "Yes".
This requirement must meet one of the options below: Option 1: From either the Work Space or Personal Space, navigate to "Settings >> Security and Privacy >> Device Password" and ensure "Device Password" is set to "On". Otherwise, this is a finding. Option 2: From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance" and ensure "Use as my device password" is set to "On" and greyed out. Otherwise, this is a finding.
Select one option to fix this requirement: Option 1: From either the Work Space or Personal Space, navigate to "Settings >> Security and Privacy >> Device Password" and set "Enable Device Password" to "On". Create a 4-digit password for device lock. Option 2: On BlackBerry Device Service, set "Apply Work Space Password to Full Device" rule to "Yes". Note: This fix procedure affects the Personal Space.
From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance". Verify "Lock Work Space After" is set to "15 Minutes", with higher values hidden. Otherwise, this is a finding.
On BlackBerry Device Service, set the IT Policy rule "Lock Device After" to "15 minutes".
On BlackBerry Device Service, verify the IT Policy rule "Application Security Timer Reset" is set to "Disallow". Otherwise, this is a finding.
On BlackBerry Device Service, set the IT Policy rule "Application Security Timer Reset" to "Disallow".
From either the Work Space or Personal Space, navigate to "Settings >> Date and Time" and verify "Set Date and Time Automatically" is set to "On". Otherwise, this is a finding.
From either the Work Space or Personal Space, navigate to "Settings >> Date and Time" and set "Set Date and Time Automatically" to "On". NOTE: This fix procedure affects both Personal and Work Spaces.
From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balance" and select "Change Password". Authenticate using the current password. Select "Password Rules" and verify "Your password must be at least 6 characters." Otherwise, this is a finding.
On BlackBerry Device Service, set the IT Policy rule "Minimum Password Length" to 6.
From either the Work Space or Personal Space, navigate to "Settings >> Security and Privacy >> Development Mode" and verify "Use Development Mode" is set to "OFF" and grayed out. Otherwise, this is a finding.
On BlackBerry Device Service, set the IT Policy rule "Restrict Development Mode" to "Yes".
If requirement BB10-2X-000220 is met, this requirement is not applicable. On BlackBerry Device Service, verify the IT Policy rule "Development Mode Access to Work Space" is set to "Disallow". Otherwise, this is a finding.
On BlackBerry Device Service, set the IT Policy rule "Development Mode Access to Work Space" to "Disallow".
On BlackBerry Device Service, verify the IT Policy rule "Install Apps From Other Sources" is set to "Disallow". Otherwise, this is a finding.
On BlackBerry Device Service, set the IT Policy rule "Install Apps From Other Sources" to "Disallow".
From the Work Space, open "BlackBerry World - Work" and select "Public". If any apps are listed under "Public", this is a finding.
On BlackBerry Device Service, on the BlackBerry solution management menu, expand "Software >> Applications", click "Manage applications", and delete all applications under "BlackBerry World Applications".
From either the Work Space or Personal Space, navigate to "Settings >> Network Connections >> Wi-Fi >> Saved" and select a saved DoD Wi-Fi profile to check. Verify "Security Type" is set to "WPA Enterprise" or "WPA2 Enterprise" and "Security Sub Type" is set to "EAP-TLS". These options should be grayed out. Otherwise, this is a finding. NOTE: Wi-Fi profiles, other than those connecting to DoD Wi-Fi networks, are not a finding. If no DoD Wi-Fi networks are saved, this requirement is NA.
On BlackBerry Device Service, select the affected Wi-Fi Profile(s), and set "EAP Security Setting" to "TLS".
From either the Work Space or Personal Space, navigate to "Settings >> Network Connections >> VPN ". Select and hold a VPN profile to check, and select "Edit Profile" to edit the VPN Profile. For each VPN Profile connecting to DoD networks: - Select the VPN Profile to edit. - Verify "Authentication Type" is set to "PKI" or "XAUTH-PKI" and grayed out. Otherwise, this is a finding. NOTE: If the VPN Profile listed under "Settings >> Network Connections >> VPN" has a brief case logo on the right side, it was created on BlackBerry Device Service published to the device. "Authentication Type" for this VPN Profile will be grayed out and enforced. If no VPN profiles are saved, this requirement is NA.
On BlackBerry Device Service, select the applicable VPN Profile and set "Authentication Type" to "PKI" or "XAUTH-PKI".
From the Work Space, navigate to "Settings >> Security and Privacy >> Certificates", and inspect "Enterprise Root Certificates" and "Enterprise Intermediate Certificates" stores. If DoD root and intermediate PKI certificates are not in the stores, this is a finding.
On BlackBerry Device Service, ensure the required ".pem" files are present in this folder: <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www>
On BlackBerry Device Service, in the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software >> Applications >> Manage applications". If there are any unauthorized instant messaging systems listed, this is a finding.
On BlackBerry Device Service: In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software >> Applications >> Manage applications". Delete the unauthorized IM system application.
From the Work Space, navigate to "Settings >> Security and Privacy >> Application Permissions" and select "All" in the "Permissions" dropdown box. For each application, ensure the requested permissions (e.g., Location, Contacts, Shared Files, etc.) are set to "On" only for AO authorized permissions. Otherwise, this is a finding. NOTE: If no applications are installed, this requirement is NA.
From the Work Space, navigate to "Settings >> Security and Privacy >> Application Permissions" and select "All" in "Permissions" dropdown box. For each application, set requested permission (e.g. Location, Contacts, Shared Files, etc.) to "On" or "Off" as identified by the AO.
From the Work Space, navigate to "Settings >> Security and Privacy >> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"). Verify the certificates listed originated from the BDS server. If the certificates do not originate from a DoD BDS server, this is a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply.
On BlackBerry Device Service, remove the corresponding .pem file from this folder: <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www>
From the Work Space, navigate to "Settings >> Security and Privacy >> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"). Verify the certificates listed originated from the BDS server. If the certificates do not originate from a DoD BDS server, this is a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply.
On BlackBerry Device Service, remove the corresponding .pem file from this folder: <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www>
From either the Work Space or Personal Space, navigate to "Settings >> About" and verify "Software Release" indicates version 10.2.1.1925, or higher. Otherwise, this is a finding.
From either the Work Space or Personal Space, navigate to "Settings >> Software Updates" and select "Check for Updates". NOTE: This fix procedure affects both Personal and Work Spaces.
From either the Work Space or Personal Space, navigate to "Settings >> BlackBerry Balanceā. Under "Work Password", ensure the maximum value in the "Password attempt limit" drop down box is less than 10, otherwise, this is a finding.
On BlackBerry Device Service, set the IT Policy rule "Maximum Password Attempts" to be less than 10.
From either the Work Space or Personal Space, navigate to "Settings >> About >> Work Space". Under "IT Policy", verify "Policy Name" value is identical to the name of the IT Policy assigned from BDS. Otherwise, this is a finding.
On BlackBerry Device Service, navigate to "BlackBerry solution management >> User >> Manage users >> <affected user's device PIN>". Select "Resend IT Policy to a device".
From the Work Space, navigate to "Settings >> Accounts". Verify all required work email accounts (with a briefcase icon) are present. Otherwise, this is a finding.
On BlackBerry Device Service, navigate to "BlackBerry solution management >> Profiles >> Manage email profiles". Verify all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management >> Profiles >> Create email profiles". Assign all required email profiles to affected user, or a group the user is a part of.
From either the Work Space or Personal Space, navigate to "Settings >> Network Connections >> Wi-Fi >> Saved". Verify all required work Wi-Fi profiles (with a briefcase icon) are present. Otherwise, this is a finding. NOTE: Additional profiles without the briefcase icon are permitted and are not a finding.
On BlackBerry Device Service, navigate to "BlackBerry solution management >> Profiles >> Manage Wi-Fi Profiles". Verify all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management >> Profiles >> Create Wi-Fi Profiles". Assign all required Wi-Fi profiles to affected user, or a group the user is a part of.
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN". Verify all required work VPN profiles (with a briefcase icon) are present. Otherwise, this is a finding.
On BlackBerry Device Service, navigate to "BlackBerry solution management -> Profiles -> Manage VPN Profiles". Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create VPN Profiles". Assign all required VPN profiles to affected user, or a group the user is a part of.
On BlackBerry Device Service: Ensure the IT Policy rule "Personal Apps Access to Work Contacts" is set to "Only BlackBerry Apps". Otherwise, this is a finding.
On BlackBerry Device Service, set the IT Policy rule "Personal Apps Access to Work Contacts" to "Only BlackBerry Apps". NOTE: This fix procedure affects both Personal and Work Spaces.
While holding the Power button from either the Work Space or Personal Space, select "Lock" to lock the device. Ensure the Work Space content is not visible on the lock screen. Otherwise, this is a finding.
On BlackBerry Device Service, set "Lock Screen Preview of Work Content" to "Disallow".
On BlackBerry Device Service, navigate to "Devices >> Device settings >> Certificate retrieval settings >> Edit Settings >> OCSP" and verify "Service URL" field is populated with the correct value. Otherwise, this is a finding.
On BlackBerry Device Service, navigate to "Devices >> Device settings >> Certificate retrieval settings >> Edit Settings >> OCSP" and set "Service URL" field to appropriate URL of the OCSP server.
From either the Work Space or Personal Space, navigate to "Settings >> Network Connections >> VPN". Select "Edit" to edit a VPN Profile. For each VPN Profile connecting to DoD networks: - Select the VPN Profile to edit. - Ensure "Gateway Type" is set to a type which supports and utilizes IPsec and SSL/TLS. Otherwise, this is a finding. NOTE: If no VPN profiles are saved, this requirement is NA.
On BlackBerry Device Service, select the affected VPN Profile for edit, and set "Gateway Type" to a type which supports and utilizes IPsec and SSL/TLS.