Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
From either the Work Space or Personal Space, while holding the Power button, select "Lock" to lock the device. Ensure "I've read & consent to terms in IS user agreem't." is displayed on the lock screen. Otherwise, this is a finding.
On BlackBerry Device Service: 1. To open the command window for the BlackBerry Enterprise Service 10 User Administration Tool, on the computer that hosts the tool, on the taskbar, click Start >> All Programs >> BlackBerry Resource Kit for BlackBerry Enterprise Service 10 >> BlackBerry Enterprise Service 10 User Administration Tool. 2. Type besuseradminclient <credentials> -set_owner_info -u <user_name>. 3. Perform any of the following actions: • To specify the owner name to display, type -name "<name>". • To specify a single line of text, type -info "I've read & consent to terms in IS user agreem't.". • To specify multiple lines of text using an input file, type -infofile <filename>. NOTE: This fix procedure affects both Personal and Work Spaces.
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance" and ensure "Work Password" is set to "On" and grayed out. Otherwise, this is a finding.
On BlackBerry Device Service, set "Password Required for Work Space" IT Policy rule to "Yes".
From either the Work Space or Personal Space, navigate to "Settings -> Security and Privacy -> Device Password" and ensure "Device Password" is set to "On". Otherwise, this is a finding.
From either the Work Space or Personal Space, navigate to "Settings -> Security and Privacy -> Device Password" and set "Enable Device Password" to "On". Create a 4-digit password for device lock. NOTE: This fix procedure affects the Personal Space.
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance", ensure "Lock Work Space After" is set to "15 Minutes", with higher values hidden. Otherwise, this is a finding.
On BlackBerry Device Service, set "Lock Device After" IT Policy rule to "15 minutes".
On BlackBerry Device Service, verify "Application Security Timer Reset" IT Policy rule is set to "Disallow". Otherwise, this is a finding.
On BlackBerry Device Service, set "Application Security Timer Reset" IT Policy rule to "Disallow".
From either the Work Space or Personal Space, navigate to "Settings -> Date and Time" and ensure "Set Date and Time Automatically" is set to "On". Otherwise, this is a finding.
From either the Work Space or Personal Space, navigate to "Settings -> Date and Time" and set "Set Date and Time Automatically" to "On". NOTE: This fix procedure affects both Personal and Work Spaces.
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance" and select "Change Password". Authenticate using the current password. Select "Password Rules" and under "Your password must contain all of the following:", "an uppercase letter" is listed. Otherwise, this is a finding.
On BlackBerry Device Service, set "Minimum Password Complexity" IT Policy rules to "At least one uppercase letter, one lowercase letter, one number, and one special character".
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance" and select "Change Password". Authenticate using the current password. Select "Password Rules" and under "Your password must contain all of the following:", "a lowercase letter" is listed. Otherwise, this is a finding.
On BlackBerry Device Service, set "Minimum Password Complexity" IT Policy rules to "At least one uppercase letter, one lowercase letter, one number, and one special character".
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance" and select "Change Password". Authenticate using the current password. Select "Password Rules" and under "Your password must contain all of the following:", ensure "a number" is listed. Otherwise, this is a finding.
On BlackBerry Device Service, set "Minimum Password Complexity" IT Policy rules to "At least one uppercase letter, one lowercase letter, one number, and one special character".
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance" and select "Change Password". Authenticate using the current password. Select "Password Rules" and ensure "Your password must be at least 8 characters." Otherwise, this is a finding.
On BlackBerry Device Service, set "Minimum Password Length" IT Policy rule to 8.
From either the Work Space or Personal Space, navigate to "Settings ->Security and Privacy -> Development Mode" and ensure "Use Development Mode" is set to "OFF" and grayed out. Otherwise, this is a finding.
On BlackBerry Device Service, set "Restrict Development Mode" IT Policy rule to "Yes". NOTE: This fix procedure affects the Personal Space.
Open "BlackBerry World - Work" and select "Public Apps". If there are any apps listed under "Public Apps", this is a finding.
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3. Delete all applications under "BlackBerry World Applications".
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> Wi-Fi -> Saved" and select a saved DoD Wi-Fi profile to check. Ensure "Security Type" is set to "WPA Enterprise" or "WPA2 Enterprise" and "Security Sub Type" is set to "EAP-TLS". These options should be grayed out. Otherwise, this is a finding. NOTE: Wi-Fi profiles, other than those connecting to DoD Wi-Fi networks, are not a finding. If no DoD Wi-Fi networks are saved,this requirement is NA.
On BlackBerry Device Service, select the affected Wi-Fi Profile, and set "Security Type" to "WPA Enterprise" or "WPA2 Enterprise", and "Security Sub Type" to "EAP-TLS".
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN ". Select and hold a VPN profile to check, and select "Edit Profile" to edit the VPN Profile. For each VPN Profile connecting to DoD networks: - Select the VPN Profile to edit. - Ensure "Authentication Type" is set to "PKI" or "XAUTH-PKI" and grayed out. Otherwise, this is a finding. NOTE: If the VPN Profile listed under "Settings -> Network Connections -> VPN" has a brief case logo on the right side, it is created on BlackBerry Device Service published to the device. "Authentication Type" for this VPN Profile will be grayed out and enforced. If no VPN profiles are saved, this requirement is NA.
On BlackBerry Device Service, select the applicable VPN Profile and set "Authentication Type" to "PKI" or "XAUTH-PKI".
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN". Select "Edit" to edit a VPN Profile. For each VPN Profile connecting to DoD networks: - Select the VPN Profile to edit. - Ensure "Gateway Type" is set to a type which supports and utilizes IPSec and SSL/TLS. Otherwise, this is a finding. NOTE: If no VPN profiles are saved, this requirement is NA.
On BlackBerry Device Service, select the affected VPN Profile for edit, and set "Gateway Type" to a type which supports and utilizes IPSec and SSL/TLS.
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3. If there are any unauthorized instant messaging systems listed, this is a finding.
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3.Delete the unauthorized IM system application.
From the Work Space, navigate to "Settings -> Security and Privacy -> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"), ensure the certificates listed originated from the BDS server. Certificates not originating from a DoD BDS server are a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply.
On BlackBerry Device Service, remove the corresponding .pem file from <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www> folder.
From the Work Space, navigate to "Settings -> Security and Privacy -> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"), ensure the certificates listed originated from the BDS server. Certificates not originating from a DoD BDS server are a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply.
On BlackBerry Device Service, remove the corresponding .pem file from <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www> folder.
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> Wi-Fi -> Saved Networks". For each saved network, ensure "Use HTTP Proxy" is set to "On" and grayed out with appropriate proxy information filled out (such as: "Proxy Server", "Proxy Port", "Username", "Password"). If "Use HTTP Proxy" is set to "Off", this is a finding. NOTE: Proxy server information can be configured on the Wi-Fi profile. When configured, all traffic, including browser traffic, will flow through the configured proxy server.
On BlackBerry Device Service, open the affected Wi-Fi Profile for edit, and set "Associated Proxy Profile" to the preconfigured Proxy Profile for DoD use.
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN -> Edit". For each VPN profile, expand the configuration to "Advanced" and ensure the "Use Proxy" checkbox is checked and grayed out, with appropriate proxy information filled out (such as: "Proxy Server", "Proxy Port", "Username", "Password"). If the "Use Proxy" checkbox is unchecked, this is a finding. NOTE: Proxy server information can be configured on the VPN profile. When configured, all traffic, including browser traffic, will flow through the configured proxy server.
On BlackBerry Device Service, open the affected VPN Profile for edit, and set "Associated Proxy Profile" to the preconfigured Proxy Profile for DoD use.
From either the Work Space or Personal Space, navigate to "Settings -> About -> Work Space". Under "IT Policy", verify "Policy Name" value is identical to the name of the IT Policy assigned from BDS. Otherwise, this is a finding.
On BlackBerry Device Service: 1. Navigate to "BlackBerry solution management -> User -> Manage users -> <affected user's device PIN>". 2. Select "Resend IT Policy to a device".
From the Work Space, navigate to "Settings -> Accounts". Verify all required work accounts (with a briefcase icon) are present. Otherwise, this is a finding.
On BlackBerry Device Service: 1. Navigate to "BlackBerry solution management -> Profiles -> Manage email profiles". 2. Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create email profiles". 3. Assign all required email profiles to affected user, or a group the user is a part of.
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> Wi-Fi -> Saved". Verify all required work Wi-Fi profiles (with a briefcase icon) are present. Otherwise, this is a finding. NOTE: Additional profiles without the breifcase icon are permitted and are not a finding.
On BlackBerry Device Service: 1. Navigate to "BlackBerry solution management -> Profiles -> Manage Wi-Fi Profiles". 2. Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create Wi-Fi Profiles". 3. Assign all required Wi-Fi profiles to affected user, or a group the user is a part of.
From either the Work Space or Personal Space, navigate to "Settings -> Network Connections -> VPN". Verify all required work VPN profiles (with a briefcase icon) are present. Otherwise, this is a finding.
On BlackBerry Device Service: 1. Navigate to "BlackBerry solution management -> Profiles -> Manage VPN Profiles". 2. Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create VPN Profiles". 3. Assign all required VPN profiles to affected user, or a group the user is a part of.
From either the Work Space or Personal Space, navigate to "Settings -> Storage and Access" and ensure "Access using Wi-Fi" is set to "Off". Otherwise, this is a finding.
From either the Work Space or Personal Space, navigate to "Settings -> Storage and Access" and set "Access using Wi-Fi" to "Off". NOTE: This fix procedure affects the Personal Space.
From either the Work Space or Personal Space, navigate to "Settings -> Media Sharing" and ensure all of "Share Music", "Share Pictures", and "Share Videos" are set to "Off". Otherwise, this is a finding.
From the Work Space, navigate to "Settings -> Media Sharing" and set all of "Share Music", "Share Pictures" and "Share Videos" to "Off". NOTE: This fix procedure affects the Personal Space.
On BlackBerry Device Service: Ensure "Personal Apps Access to Work Contacts" IT Policy rule is set to "Only RIM Apps". Otherwise, this is a finding.
On BlackBerry Device Service, set "Personal Apps Access to Work Contacts" IT Policy rule to "Only RIM Apps". NOTE: This fix procedure affects both Personal and Work Spaces.
From either the Work Space or Personal Space, navigate to “Settings -> About” and ensure “Software Release” indicates version 10.1.X.X. Otherwise, this is a finding.
From either the Work Space or Personal Space, navigate to “Settings -> Software Updates” and select “Check for Updates”. NOTE: This fix procedure affects both Personal and Work Spaces.
On BlackBerry Device Service, verify "Work App Access to Shared Files in the Personal Space" IT Policy rule is set to "Disallow". Otherwise, this is a finding.
On BlackBerry Device Service, set "Work App Access to Shared Files in the Personal Space" IT Policy rule to "Disallow".
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance" and ensure "Work Password" is set to "On" and grayed out. Otherwise, this is a finding.
On BlackBerry Device Service, set "Password Required for Work Space" IT Policy rule to "Yes".
From either the Work Space or Personal Space, navigate to "Settings -> Security and Privacy" and verify "Smart Card" option is present. Otherwise, this is a finding.
From either the Work Space or Personal Space, navigate to "Settings -> Security and Privacy" and verify "Smart Card" option is present. Otherwise, this is a finding.
From the Work Space, navigate to "Settings -> Security and Privacy -> Certificates", and inspect "Enterprise Root Certificates" and "Enterprise Intermediate Certificates" stores. If DoD root and intermediate PKI certificates are not in the stores, this is a finding.
On BlackBerry Device Service, verify the "SCEP Profile" is configured properly for DoD SCEP server. Ensure DoD certificates are available through SCEP.
From the Work Space, navigate to "Settings -> Security and Privacy -> Application Permissions" and select "All" in the "Permissions" dropdown box. For each application, ensure the requested permissions (e.g., Location, Contacts, Shared Files, etc.) are set to "On" only for DoD authorized permissions. Otherwise, this is a finding. NOTE: If no applications are installed, this requirement is NA.
From the Work Space, navigate to "Settings -> Security and Privacy -> Application Permissions" and select "All" in "Permissions" dropdown box. For each application, set requested permission (e.g. Location, Contacts, Shared Files, etc.) to "On" or "Off" as authorized by DoD. NOTE: This fix procedure affects both Personal and Work Spaces.
From either the Work Space or Personal Space, navigate to "Settings -> BlackBerry Balance. Under "Work Password", ensure the maximum value in the "Password attempt limit" drop down box is not greater than 10 (or organization defined number). Otherwise, this is a finding.
On BlackBerry Device Service, set "Maximum Password Attempts" IT Policy rule to 10 (or the organization defined value).
On BlackBerry Device Service, navigate to the Servers and components menu and expand BlackBerry Solution topology >> BlackBerry Domain >> Component view >> BlackBerry Device Service. Click the name of the BlackBerry Device Service instance. Verify in the Instance associations pane, the preconfigured Proxy Profile for DoD use is shown as the value for the Proxy profile. If the preconfigured Proxy Profile for DoD use is not shown for the value for the Proxy profile. this is a finding.
On BlackBerry Device Service, navigate to the Servers and components menu and expand BlackBerry Solution topology >> BlackBerry Domain >> Component view >> BlackBerry Device Service. Click the name of the BlackBerry Device Service instance and click Edit instance. In the Instance associations section, in the Proxy profile drop-down list, select the preconfigured Proxy Profile for DoD use. Click Save all.
Navigate to "Settings -> About" and then "Software Release"; note the version. If the version indicated is 10.1.x or lower, this is a finding. If the version indicated is 10.2.x or higher, the BlackBerry 10.2.x OS STIG must be applied.
Update or replace the BlackBerry 10 smartphone to version 10.2.x or higher and apply the BlackBerry 10.2.x OS STIG.