BlackBerry Enterprise Mobility Server 3.x Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- BEMS-03-002600
- Vuln IDs
-
- V-254706
- Rule IDs
-
- SV-254706r861843_rule
Checks: C-58317r861841_chk
Verify BEMS has been configured with the following administrator groups/roles, each group/role has required permissions, and at least one user has been assigned to each Administrator group/role: Server primary administrator, auditor. Procedure for Server Primary Administrator: 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "Dashboard Administrators". 3. Confirm the Administrator role for the primary server administrator has been assigned the dashboard role of Admin. 4. Verify in Active Directory (AD) at least one member has been assigned to the BEMS administrator group. (Note: Actual group name may be different.) Procedure for Auditor: 1. Verify in AD an auditor group has been set up with at least one member. 2. Browse to the log repository. 3. Right-click on the folder. 4. Select "Properties". 5. Select the "Security" tab. 6. Confirm the auditor security group is listed. If required administrator roles have not been set up on BEMS and at least one user has not been assigned to each role, this is a finding.
Fix: F-58263r861842_fix
Configure BEMS to have at least one user in the following Administrator roles: Server primary administrator, auditor. 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "Dashboard Administrators". 3. Click "Add Group". 4. In the "Active Directory Security Group" field, type the name of the Microsoft Active Directory security group. 5. Click "Save". 6. Repeat steps 3 through 5 to add additional security groups. 7. For the server primary administrator, the default role of Admin meets the required roles and no additional configuration is needed. 8. For the Auditor role, complete the following steps: - In AD, create a domain auditor group and assign personnel designated as auditors to that group. - Browse to the log repository. - Right-click on the folder. - Select "Properties". - Select the "Security" tab. - Click "Edit". - Click "Add". - Type the name of the user group. - Confirm that only the necessary groups have rights to the folder (CREATOR OWNER, SYSTEM, Administrators, Auditors). - Set proper permissions for auditors (Read, List folder contents, Read & Execute).
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000163
- Version
- BEMS-03-002700
- Vuln IDs
-
- V-254707
- Rule IDs
-
- SV-254707r861846_rule
Checks: C-58318r861844_chk
Verify BEMS has been configured with the following administrator groups/roles, each group/role has required permissions, and at least one user has been assigned to each Administrator group/role: Server primary administrator, auditor. Procedure for Server Primary Administrator: 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "Dashboard Administrators". 3. Confirm the Administrator role for the primary server administrator has been assigned the dashboard role of Admin. 4. Verify in Active Directory (AD) at least one member has been assigned to the BEMS administrator group. (Note: Actual group name may be different.) Procedure for Auditor: 1. Verify in AD an auditor group has been set up with at least one member. 2. Browse to the log repository. 3. Right-click on the folder. 4. Select "Properties". 5. Select the "Security" tab. 6. Confirm the auditor security group is listed. If required administrator roles have not been set up on BEMS and at least one user has not been assigned to each role, this is a finding.
Fix: F-58264r861845_fix
Configure BEMS to have at least one user in the following Administrator roles: Server primary administrator, auditor. 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "Dashboard Administrators". 3. Click "Add Group". 4. In the "Active Directory Security Group" field, type the name of the Microsoft Active Directory security group. 5. Click "Save". 6. Repeat steps 3 through 5 to add additional security groups. 7. For the server primary administrator, the default role of Admin meets the required roles and no additional configuration is needed. 8. For the Auditor role, complete the following steps: - In AD, create a domain auditor group and assign personnel designated as auditors to that group. - Browse to the log repository. - Right-click on the folder. - Select "Properties". - Select the "Security" tab. - Click "Edit". - Click "Add". - Type the name of the user group. - Confirm that only the necessary groups have rights to the folder (CREATOR OWNER, SYSTEM, Administrators, Auditors). - Set proper permissions for auditors (Read, List folder contents, Read & Execute).
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000164
- Version
- BEMS-03-002800
- Vuln IDs
-
- V-254708
- Rule IDs
-
- SV-254708r861849_rule
Checks: C-58319r861847_chk
Verify BEMS has been configured with the following administrator groups/roles, each group/role has required permissions, and at least one user has been assigned to each Administrator group/role: Server primary administrator, auditor. Procedure for Server Primary Administrator: 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "Dashboard Administrators". 3. Confirm the Administrator role for the primary server administrator has been assigned the dashboard role of Admin. 4. Verify in Active Directory (AD) at least one member has been assigned to the BEMS administrator group. (Note: Actual group name may be different.) Procedure for Auditor: 1. Verify in AD an auditor group has been set up with at least one member. 2. Browse to the log repository. 3. Right-click on the folder. 4. Select "Properties". 5. Select the "Security" tab. 6. Confirm the auditor security group is listed. If required administrator roles have not been set up on BEMS and at least one user has not been assigned to each role, this is a finding.
Fix: F-58265r861848_fix
Configure BEMS to have at least one user in the following Administrator roles: Server primary administrator, auditor. 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "Dashboard Administrators". 3. Click "Add Group". 4. In the "Active Directory Security Group" field, type the name of the Microsoft Active Directory security group. 5. Click "Save". 6. Repeat steps 3 through 5 to add additional security groups. 7. For the server primary administrator, the default role of Admin meets the required roles and no additional configuration is needed. 8. For the Auditor role, complete the following steps: - In AD, create a domain auditor group and assign personnel designated as auditors to that group. - Browse to the log repository. - Right-click on the folder. - Select "Properties". - Select the "Security" tab. - Click "Edit". - Click "Add". - Type the name of the user group. - Confirm that only the necessary groups have rights to the folder (CREATOR OWNER, SYSTEM, Administrators, Auditors). - Set proper permissions for auditors (Read, List folder contents, Read & Execute).
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- BEMS-03-003800
- Vuln IDs
-
- V-254709
- Rule IDs
-
- SV-254709r861852_rule
Checks: C-58320r861850_chk
Review the BEMS configuration to determine whether a DOD-approved firewall is installed or if the platform operating system provides a firewall service that can restrict both inbound and outbound traffic by TCP/UDP port and IP address. If there is not a host-based firewall present on BEMS, this is a finding.
Fix: F-58266r861851_fix
Install a DOD-approved firewall.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- BEMS-03-003900
- Vuln IDs
-
- V-254710
- Rule IDs
-
- SV-254710r861855_rule
Checks: C-58321r861853_chk
Ask the BEMS administrator for a list of ports, protocols, and IP address ranges necessary to support BEMS functionality. A list can usually be found in the STIG Supplemental document or MDM product documentation. Compare the list against the configuration of the firewall and identify discrepancies. If the host-based firewall is not configured to support only those ports, protocols, and IP address ranges necessary for operation, this is a finding.
Fix: F-58267r861854_fix
Configure the firewall on BEMS to only permit ports, protocols, and IP address ranges necessary for operation.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- BEMS-03-004000
- Vuln IDs
-
- V-254711
- Rule IDs
-
- SV-254711r861858_rule
Checks: C-58322r861856_chk
Ask the BEMS administrator for a list of ports, protocols, and services that have been configured on the host-based firewall of BEMS or generate the list by inspecting the firewall. Verify all allowed ports, protocols, and services are included on the DOD PPSM CAL list. If any allowed ports, protocols, and services on the MDM host-based firewall are not included on the DOD PPSM CAL list, this is a finding.
Fix: F-58268r861857_fix
Turn off any ports, protocols, and services on the BEMS host-based firewall that are not on the DOD PPSM CAL list.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- BEMS-03-011400
- Vuln IDs
-
- V-254712
- Rule IDs
-
- SV-254712r861861_rule
Checks: C-58323r861859_chk
Verify BEMS has been configured to use only approved versions of TLS as follows: 1. Find the xml file "jetty.xml" located in the BEMS install directory on the BEMS host Windows server. 2. Find the "ExcludeProtocols" field. 3. Verify if unauthorized versions of SSL and TLS are listed in the "jetty.xml" file. <Set name="ExcludeProtocols"> <Array type="java.lang.String"> <Item>TLSv1</Item> <Item>TLSv1.1</Item> <Item>SSL</Item> <Item>SSLv2</Item> <Item>SSLv2Hello</Item> <Item>SSLv3</Item> If BEMS has not been configured to use only approved versions of TLS and the Exclude file does not include all of the above TLS and SSL protocols, this is a finding.
Fix: F-58269r861860_fix
Configure BEMS to use approved versions of TLS. 1. Find the xml file "jetty.xml" located in the BEMS install directory on the BEMS host Windows server. 2. Find the "ExcludeProtocols" field and add all unauthorized versions or SSL and TLS. <Set name="ExcludeProtocols"> <Array type="java.lang.String"> <Item>TLSv1</Item> <Item>TLSv1.1</Item> <Item>SSL</Item> <Item>SSLv2</Item> <Item>SSLv2Hello</Item> <Item>SSLv3</Item> 3. Save the file. 4. Restart the BEMS server.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- BEMS-03-011500
- Vuln IDs
-
- V-254713
- Rule IDs
-
- SV-254713r861864_rule
Checks: C-58324r861862_chk
Verify BEMS has been configured to remove all export ciphers (automatically implemented when BEMS is in FIPS mode). Verify BEMS-03-014800 has been implemented. If BEMS has been configured to use export ciphers, this is a finding.
Fix: F-58270r861863_fix
Configure BEMS to remove all export ciphers. This requirement is met when BEMS is configured in FIPS mode. See BEMS-03-01480.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- BEMS-03-013300
- Vuln IDs
-
- V-254714
- Rule IDs
-
- SV-254714r861867_rule
Checks: C-58325r861865_chk
Verify BEMS has been configured with the following administrator groups/roles, each group/role has required permissions, and at least one user has been assigned to each Administrator group/role: Server primary administrator, auditor. Procedure for Server Primary Administrator: 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "Dashboard Administrators". 3. Confirm the Administrator role for the primary server administrator has been assigned the dashboard role of Admin. 4. Verify in Active Directory (AD) at least one member has been assigned to the BEMS administrator group. (Note: Actual group name may be different.) Procedure for Auditor: 1. Verify in AD an auditor group has been set up with at least one member. 2. Browse to the log repository. 3. Right-click on the folder. 4. Select "Properties". 5. Select the "Security" tab. 6. Confirm the auditor security group is listed. If required administrator roles have not been set up on BEMS and at least one user has not been assigned to each role, this is a finding.
Fix: F-58271r861866_fix
Configure BEMS to have at least one user in the following Administrator roles: Server primary administrator, auditor. 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "Dashboard Administrators". 3. Click "Add Group". 4. In the "Active Directory Security Group" field, type the name of the Microsoft Active Directory security group. 5. Click "Save". 6. Repeat steps 3 through 5 to add additional security groups. 7. For the server primary administrator, the default role of Admin meets the required roles and no additional configuration is needed. 8. For the Auditor role, complete the following steps: - In AD, create a domain auditor group and assign personnel designated as auditors to that group. - Browse to the log repository. - Right-click on the folder. - Select "Properties". - Select the "Security" tab. - Click "Edit". - Click "Add". - Type the name of the user group. - Confirm that only the necessary groups have rights to the folder (CREATOR OWNER, SYSTEM, Administrators, Auditors). - Set proper permissions for auditors (Read, List folder contents, Read & Execute).
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- BEMS-03-013400
- Vuln IDs
-
- V-254715
- Rule IDs
-
- SV-254715r861870_rule
Checks: C-58326r861868_chk
Verify BEMS is configured for Windows Authentication for the database connection as follows: In the Database Information dialog box, verify "Windows Authentication" is selected. If "Windows Authentication" is not selected for the BEMS database connection, this is a finding.
Fix: F-58272r861869_fix
Set up Windows Authentication for the database connection on the BEMS console. In the Database Information dialog box, perform the following actions: 1. In the "Host" field, type the instance name of the SQL Server. 2. In the "Database" name field, type the name for the BEMS-Core database. 3. In the "Port" field, type the port number that connects to the SQL Server. 4. Select "Windows Authentication". 5. Click "Next".
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- BEMS-03-013500
- Vuln IDs
-
- V-254716
- Rule IDs
-
- SV-254716r861873_rule
Checks: C-58327r861871_chk
Verify BEMS has been configured to use HTTPS as follows: 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "BlackBerry Dynamics". 3. In the Protocol drop-down list, verify "HTTPS" is selected. If HTTPS is not configured on BEMS, this is a finding.
Fix: F-58273r861872_fix
Configure BEMS to use HTTPS as follows: 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "BlackBerry Dynamics". 3. In the Protocol drop-down list, select "HTTPS".
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- BEMS-03-013600
- Vuln IDs
-
- V-254717
- Rule IDs
-
- SV-254717r861876_rule
Checks: C-58328r861874_chk
Verify a DOD SSL certificate has been installed on BEMS as follows: 1. Open the browser. 2. Browse to the BEMS dashboard. 3. Select SSL certificate and view the certificate. 4. Verify the certificate is a DOD certificate (has the DOD CA listed in the certificate). If the SSL certificate installed on BEMS is not a DOD certificate, this is a finding.
Fix: F-58274r861875_fix
Replace the auto-generated BEMS SSL certificate with a DOD certificate as follows: 1. Generate a CSR request and obtain a certificate from the DOD CA. 2. Import the certificate into the BEMS keystore. 3. Update the certificate passwords in BEMS.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002361
- Version
- BEMS-03-013700
- Vuln IDs
-
- V-254718
- Rule IDs
-
- SV-254718r870239_rule
Checks: C-58329r870239_chk
Verify the BEMS inactivity timeout is set to 15 minutes or less: 1. Find the xml file "jetty.xml" located in the BEMS install directory on the BEMS host Windows server. 2. Find the "maxIdleTime" field. (Note: "idleTimeout" may be the field, depending on the version of BEMS.) 3. Verify it is set to 900 or less (seconds). (Note: time may be in milliseconds, depending on the version of BEMS. In this case, the value would be 900000.) If the BEMS inactivity timeout is not set to 15 minutes (900 seconds) or less, this is a finding.
Fix: F-58275r861878_fix
Configure BEMS with an inactivity timeout of 15 minutes or less. 1. Find the xml file "jetty.xml" located in the BEMS install directory on the BEMS host Windows server. 2. Find the "maxIdleTime" field and set it to 900 or less (seconds). (Note: "idleTimeout" may be the field and time may be in milliseconds, depending on the version of BEMS. In this case, the value would be 900000.) 3. Save the file. 4. Restart the BEMS server.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- BEMS-03-013800
- Vuln IDs
-
- V-254719
- Rule IDs
-
- SV-254719r861882_rule
Checks: C-58330r861880_chk
This requirement is not applicable if the Mail service (Push Notifications support for BlackBerry Work) is not enabled on BEMS. Verify the mail service in BEMS is configured for Windows Authentication for the database connection as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Mail". 2. Click "Database". 3. In the "Server" field, type the Microsoft SQL Server host name and instance. 4. In the "Database" field, type the database name. 5. In the Windows Authentication drop-down list, verify "Windows Authentication" is selected. If "Windows Authentication" is not selected for the mail service database connection, this is a finding.
Fix: F-58276r861881_fix
Set up Windows Authentication for the database connection for the mail service in BEMS: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Mail". 2. Click "Database". 3. In the "Server" field, type the Microsoft SQL Server host name and instance. 4. In the "Database" field, type the database name. 5. In the Windows Authentication drop-down list, select "Windows Authentication". 6. Click "Save".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- BEMS-03-013900
- Vuln IDs
-
- V-254720
- Rule IDs
-
- SV-254720r861885_rule
Checks: C-58331r861883_chk
This requirement is not applicable if the Mail service (Push Notifications support for BlackBerry Work) is not enabled on BEMS. Verify Windows Integrated Authentication for the Exchange connection for the Mail service has been set up in BEMS as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Mail". 2. Click "Microsoft Exchange". 3. Under "Enter Service Account Details", verify "Use Windows Integrated Authentication" has been selected. If Windows Integrated Authentication for the Exchange connection for the Mail service has not been set up in BEMS, this is a finding.
Fix: F-58277r861884_fix
Set up Windows Integrated Authentication for the Exchange connection for the Mail service in BEMS: 1. Log on to BEMS with the service account that will be configured. 2. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Mail". 3. Click "Microsoft Exchange". 4. Under "Enter Service Account Details", select the "Use Windows Integrated Authentication" check box. 5. Click "Save".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- BEMS-03-014000
- Vuln IDs
-
- V-254721
- Rule IDs
-
- SV-254721r861888_rule
Checks: C-58332r861886_chk
This requirement is not applicable if the Mail service (Push Notifications support for BlackBerry Work) is not enabled on BEMS. Verify Enable SSL LDAP for LDAP Lookup for users for the Mail service is configured in BEMS as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Mail". 2. Click "User Directory Lookup". 3. If the "Enable LDAP Lookup" has been selected, verify the "Enable SSL LDAP" check box is also selected. When LDAP Lookup for user has been configured on BEMS, if Enable SSL LDAP is not configured, this is a finding.
Fix: F-58278r861887_fix
Enable SSL LDAP when using LDAP Lookup for users for the Mail service in BEMS as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Mail". 2. Click "User Directory Lookup". 3. Select the "Enable LDAP Lookup" check box. 4. Select the "Enable SSL LDAP" check box. 5. Click "Save".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- BEMS-03-014100
- Vuln IDs
-
- V-254722
- Rule IDs
-
- SV-254722r861891_rule
Checks: C-58333r861889_chk
This requirement is not applicable if the Mail service (Push Notifications support for BlackBerry Work) is not enabled on BEMS. Verify Enable SSL LDAP for LDAP Lookup for certificates for the Mail service is configured in BEMS as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Mail", and then click "Certificate Directory Lookup". 2. If the "Enable LDAP Lookup" has been selected, verify the "Enable SSL LDAP" check box is also selected. When LDAP Lookup for certificates has been configured on BEMS, if Enable SSL LDAP is not configured, this is a finding.
Fix: F-58279r861890_fix
Enable SSL LDAP when using LDAP Lookup for certificates for the Mail service in BEMS as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Mail". 2. Click "Certificate Directory Lookup". 3. Select the "Enable LDAP Lookup" check box. 4. Select the "Enable SSL LDAP" check box. 5. Click "Save".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- BEMS-03-014200
- Vuln IDs
-
- V-254723
- Rule IDs
-
- SV-254723r861894_rule
Checks: C-58334r861892_chk
This requirement is not applicable if the BlackBerry Connect service is not enabled on BEMS. Verify the BlackBerry Connect service in BEMS is configured for Windows Authentication for the database connection as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Connect". 2. Click "Database". 3. In the "Database" field, type the database name. 4. In the "Windows Authentication" drop-down list, verify "Windows Authentication" is selected. If "Windows Authentication" is not selected for the BlackBerry Connect database connection, this is a finding.
Fix: F-58280r861893_fix
Set up Windows Authentication for the database connection for the BlackBerry Connect service in BEMS: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Connect". 2. Click "Database". 3. In the "Database" field, type the database name. 4. In the "Windows Authentication" drop-down list, select "Windows Authentication". 5. Click "Save".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- BEMS-03-014300
- Vuln IDs
-
- V-254724
- Rule IDs
-
- SV-254724r861897_rule
Checks: C-58335r861895_chk
This requirement is not applicable if the BlackBerry Connect service is not enabled on BEMS. Verify SSL is enabled for the BlackBerry Connect service and a DOD certificate is used as follows: 1. Browse to FQDN of the BEMS Connect server(s) on port 8082. 2. Click on the SSL certificate to verify it has been issued by the DOD CA. 3. Repeat steps 1 and 2 for each BEMS server that has the Connect service added to it. If SSL is not enabled for BlackBerry Connect and if the SSL certificate is not a DOD CA issued certificate, this is a finding.
Fix: F-58281r861896_fix
Configure BlackBerry Connect to enable SSL with a DOD certificate. 1. Submit a CSR request to the DOD CA. 2. In BEMS Select "SSL Certificate". 3. Select "Choose File" and select the new SSL Certificate and type the "Password". 4. Configure BlackBerry Connect to send the request over SSL (see page 20 of the BEMS Configuring the BlackBerry Connect Service document). 5. Configure Connect to use SSL with BlackBerry Proxy (see page 20 of the BEMS Configuring the BlackBerry Connect Service document).
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- BEMS-03-014400
- Vuln IDs
-
- V-254725
- Rule IDs
-
- SV-254725r861900_rule
Checks: C-58336r861898_chk
This requirement is not applicable if the BlackBerry Docs service is not enabled on BEMS. Verify the BlackBerry Docs service in BEMS is configured for Windows Authentication for the database connection as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Docs". 2. Click "Database". 3. In the "Database" field, type the database name. 4. In the Windows Authentication drop-down list, verify "Windows Authentication" is selected. If "Windows Authentication" is not selected for the BlackBerry Docs database connection, this is a finding.
Fix: F-58282r861899_fix
Set up Windows Authentication for the database connection for the BlackBerry Docs service in BEMS: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Docs". 2. Click "Database". 3. In the "Database" field, type the database name. 4. In the Windows Authentication drop-down list, select "Windows Authentication". 5. Click "Save".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- BEMS-03-014500
- Vuln IDs
-
- V-254726
- Rule IDs
-
- SV-254726r861903_rule
Checks: C-58337r861901_chk
This requirement is not applicable if the BlackBerry Docs service is not enabled on BEMS. Verify NTLM authentication is enabled for the BlackBerry Docs service as follows: 1. In the BEMS Dashboard, under "Good Services Configuration", click "Docs". 2. Click "Web Proxy". 3. Select "Use Web Proxy". 4. In the Proxy Server Authentication Type drop-down list, verify "NTLM authentication" is selected. If NTLM authentication is not enabled for the BlackBerry Docs service, this is a finding.
Fix: F-58283r861902_fix
Configure NTLM authentication for the BlackBerry Docs service as follows: 1. In the BEMS Dashboard, under "Good Services Configuration", click "Docs". 2. Click "Web Proxy". 3. Select the "Use Web Proxy". 4. In the Proxy Server Authentication Type drop-down list, select "NTLM authentication". 5. Click "Save".
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-001453
- Version
- BEMS-03-014600
- Vuln IDs
-
- V-254727
- Rule IDs
-
- SV-254727r861906_rule
Checks: C-58338r861904_chk
This requirement is not applicable if the BlackBerry Docs service is not enabled on BEMS. Verify the BlackBerry Docs service is configured to use SSL for LDAP Lookup to connect to the Office Web App Server (e.g., SharePoint) as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Docs". 2. Click "Settings". 3. Verify "Use SSL for LDAP" is selected. If SSL for LDAP is not enabled for the BlackBerry Docs service, this is a finding.
Fix: F-58284r861905_fix
This requirement is not applicable if the BlackBerry Docs service is not enabled on BEMS. Configure the BlackBerry Docs service to use SSL for LDAP Lookup to connect to the Office Web App Server (e.g., SharePoint) as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Docs". 2. Click "Settings". 3. Select the "Enable Kerberos Constrained Delegation" check box to allow Docs to use Kerberos constrained delegation. 4. Enter each of the Microsoft SharePoint Online domains that will be made available. 5. Enter the URL for the approved Office Web App Server. 6. Provide the Microsoft Active Directory user domains (separated by commas) and then enter the corresponding LDAP Port. 7. Select the "Use SSL for LDAP" check box. 8. Click "Save".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- BEMS-03-014700
- Vuln IDs
-
- V-254728
- Rule IDs
-
- SV-254728r861909_rule
Checks: C-58339r861907_chk
This requirement is not applicable if the BlackBerry Docs service is not enabled on BEMS. Verify audit logging is enabled for the BlackBerry Docs service as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Docs". 2. Click "Audit". 3. On the "Audit Settings" tab, verify "Enable Audit Logs" is selected. If audit logging is not enabled for the BlackBerry Docs service, this is a finding.
Fix: F-58285r861908_fix
Enable audit logging for the BlackBerry Docs service as follows: 1. In the BEMS Dashboard, under "BlackBerry Services Configuration", click "Docs". 2. Click "Audit". 3. On the "Audit Settings" tab, select the "Enable Audit Logs" check box. 4. Click "Save".
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- BEMS-03-014800
- Vuln IDs
-
- V-254729
- Rule IDs
-
- SV-254729r864567_rule
Checks: C-58340r861910_chk
Verify FIPS Mode is enabled for BEMS. 1. Under BEMS Systems Settings select "BEMS Configuration". 2. Select "FIPS Mode". 3. Confirm "Enable FIPS Mode for Cluster" has been selected. If "Enable FIPS Mode for Cluster" is not selected, this is a finding.
Fix: F-58286r861911_fix
Enable FIPS Mode for BEMS. 1. In the BEMS Dashboard, under "BEMS Configuration", click "FIPS Mode". 2. Check the box "Enable FIPS Mode for Cluster". 3. Click "Save".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- BEMS-03-014900
- Vuln IDs
-
- V-254730
- Rule IDs
-
- SV-254730r861915_rule
Checks: C-58341r861913_chk
This requirement is not applicable if the Connect service is not enabled on BEMS. Verify that Web Proxy Configuration has been configured. 1. Under "BlackBerry Services Configuration" select "Connect". 2. Select "Web Proxy". 3. Confirm "Use Web Proxy" has been checked. If "Use Web Proxy" has not been selected, this is a finding.
Fix: F-58287r861914_fix
Configure Web Proxy Configuration for the Connect service. 1. In the BEMS dashboard under "BlackBerry Services Configuration" click "Connect". 2. Click "Web Proxy". 3. Check the box for "Use Web Proxy". 4. Add "Proxy Address". 5. Add "Proxy Port". 6. Set "Proxy Server Authentication Type" to "Digest".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- BEMS-03-015000
- Vuln IDs
-
- V-254731
- Rule IDs
-
- SV-254731r861918_rule
Checks: C-58342r861916_chk
This requirement is not applicable if the Presence service is not enabled on BEMS. Verify that Domain whitelisting has been configured. 1. Under the BlackBerry Service Configuration select "Presence". 2. Select "Settings". 3. Confirm "Enable domain whitelisting" has been checked. If "Enable domain whitelisting" is not selected, this is a finding.
Fix: F-58288r861917_fix
Configure Domain Whitelisting for the Presence service. 1. Under the BlackBerry Service Configuration select "Presence". 2. Select "Settings". 3. Confirm "Enable domain whitelisting" has been checked. 4. Click the plus sign and add the domain to whitelist.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- BEMS-03-015100
- Vuln IDs
-
- V-254732
- Rule IDs
-
- SV-254732r861921_rule
Checks: C-58343r861919_chk
This requirement is not applicable if the Docs service for BEMS is not enabled. Verify that the authentication type is set to NTLM if a web proxy is used. 1. Under the "BlackBerry Services Configuration", select "Docs". 2. Under the "Proxy Server Authentication Type", ensure "NTLM" is Selected. If "NTLM" is not selected, this is a finding.
Fix: F-58289r861920_fix
Configure the Docs Web Proxy Authentication type within BEMS. 1. Under the "BlackBerry Services Configuration", select "Docs". 2. Select "Web Proxy Configuration". 3. Under "Proxy Server Authentication Type" Select "NTLM".