Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the following procedure. 1. Make a list of all IT Policies that have been assigned to BlackBerry user accounts. The list of IT Policies set up on the BES can be viewed as follows (do not list the default IT Policy) (Use Method #1 or Method #2 below): Method #1 BAS >> BlackBerry solution management box >> Policy >> Manage IT policies. Look at each IT policy listed under Manage IT policies to be checked. -Click on the policy name. -Click on "View users with IT policy." -Click Search. A list of all users assigned to the policy will be shown. For each policy that has users assigned to it, complete steps. Method #2 -Launch and log into the BlackBerry Monitoring Service. -On the monitoring menu, expand Reporting. -Click "Create custom report". -Select the following fields for the report: **Select report type: User. **Report title: IT Policies on BES. **Select the following columns: "IT policy name" and "User name." **Sort by "IT policy name". **Report format: PDF recommended. **Generate report. 2. Check each "Required" IT Policy rule listed in Table 1, BlackBerry STIG Configuration Tables. (There are approximately 125 rules with required configuration settings.) Note: All IT policy rules that have not been set correctly and the name of the IT policy currently being reviewed. The name of each IT policy that has an IT policy rule not set correctly should be noted in VMS. Note: Table 1 shows which Check STIG ID # should be marked as a finding for each IT policy rule not set correctly. 3. Repeat step 2 for each IT Policy that has users assigned to it. 4. In VMS, for each check with a finding, list the IT Policies that were found to be noncompliant. ***** For this check, verify IT Policy rule “Password Required” (Device Only policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Handheld must be set to lock after 15 minutes or less of inactivity. *****For this check, set IT Policy rule "Maximum Security Timeout" (Device-Only policy group) to "15 or less". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Maximum Security Timeout" (Device-Only policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
*****For this check, set IT Policy rule "Content Protection Strength" (Security policy group) to "Stronger or Strongest". Data-at-Rest encryption (Content Protection) must be enabled on BlackBerry devices. Note: When Content Protection is enabled in BES 4.1.4 and earlier and BlackBerry handheld software version before 4.5, the BES system administrator cannot remotely unlock a BlackBerry device and remotely reset the device password. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Content Protection Strength" (Security policy group) is set as required. This check can also be verified on a sample of site BlackBerrys (3-4 devices) but the preferred procedure is to verify on the BES. Use the following procedure on BlackBerry devices: Settings >> Options >> Security Options >> General Settings >> Content Protection Verify Content Protection is set to Enabled. Verify the setting cannot be changed. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: DoD BlackBerry users must apply the following Bluetooth controls: Bluetooth data transmissions, such as syncing to the desktop or transfer of data files, on wireless email devices are disabled except for the Bluetooth CAC reader (i.e., Bluetooth Smart Card Reader [SCR]). Bluetooth for voice transmissions, such as the Bluetooth headset, is authorized if a DoD-approved headset is used. ***** For this check, set IT Policy rule "Disable Bluetooth" (Bluetooth policy group) to "Yes" or "No", depending on if the Bluetooth Smart Card Reader (SCR) or an approved Bluetooth headset is used at the site. Set to "No" if used. Set to "Yes" if not used. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Bluetooth" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Show Application Loader" (Desktop-Only policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Show Application Loader" (Desktop-Only policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detail Policy Requirements: If BlackBerry Wi-Fi service is not authorized for use at the site, the following conditions apply: A BlackBerry WLAN IT policy has been set up for the site on the BES and is configured as shown in Table 1, BlackBerry STIG Configuration Tables. *****Set IT Policy rule "Disable Wi-Fi" (WLAN policy group) to "Yes". If WLAN use is authorized, set to "No". Check procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). Interview the BES Administrator and determine if BlackBerry Wi-Fi is authorized. *****Verify "Disable Wi-Fi" has been configured as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1400-01 (V0003545 ) for detailed policy requirements. *****For this check, Set IT Policy rule "Minimum Password Length" (Device Only policy group) to 6 or more. If CAC authentication is used, set to 6, 7, or 8 (it is recommended that the password length equal the CAC PIN length). Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). Interview the ISSO and administrator. Verify CAC authentication or PIN authentication is used. Determine if software certificates are used on the BlackBerry. *****Verify IT Policy rule "Password Required" (Device Only policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1400-01 (V0003545 ) for detailed policy requirements. *****For this check, Set IT Policy rule "User Can Disable Passwords" (Device Only policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "User Can Disable Passwords" (Device Only policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1400-01 (V0003545 ) for detailed policy requirements. *****For this check, Set IT Policy rule "Set Password Timeout" (Password policy group) to "15". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Set Password Timeout" (Password policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1400-01 (V0003545) for detailed policy requirements. *****For this check, Set IT Policy rule "Set Maximum Password Attempts" (Password policy group) to "10 or less". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Set Maximum Password Attempts" (Password policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1400-01 (V0003545) for detailed policy requirements. *****For this check, Set IT Policy rule "Suppress Password Echo" (Password policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Suppress Password Echo" (Password policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1400-01 (V0003545) for detailed policy requirements. *****For this check, Set IT Policy rule "Forbidden Passwords" (Password policy group) to "List forbidden passwords based on local security policies". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Forbidden Passwords" (Password policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1400-01 (V0003545) for detailed policy requirements. *****For this check, Set IT Policy rule "Reset to Factory Defaults on Wipe" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Reset to Factory Defaults on Wipe" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detail Policy Requirements: All PDAs and smartphones must display the following banner during device unlock/logon: A. Use this banner for desktops, laptops, and other devices accommodating banners of 1300 characters. The banner shall be implemented as a click-through banner at logon (to the extent permitted by the operating system), meaning it prevents further activity on the information system unless and until the user executes a positive action to manifest agreement by clicking on a box indicating "OK."] You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details. B. For BlackBerrys and other PDAs/PEDs with severe character limitations: I've read & consent to terms in IS user agreem't. Check Procedures: Work with the SA to review the configuration of the PDA security management server or security policy configured on the PDA/smartphone. Review a sample of devices to check that the required banner is being used. Note: Depending on the system, this setting could be set on the management server or on the handheld device. *****Set IT Policy rule “Lock Owner Info“ (Common policy group) to “1 (Lock Information text) or 3 (Lock both Name and Information text)“. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545 ). *****Verify the IT Policy rule “Lock Owner Info" has been configured as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detail Policy Requirements: See Check WIR1455-01 for policy information. *****Set IT Policy rule “Set Owner Info" (Common policy group) to “I've read & consent to terms in IS user agreem't”. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify the IT Policy rule “Set Owner Info“ has been configured as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Pairing" (Bluetooth policy group) to "Yes" or "No", depending on if the Bluetooth Smart Card Reader (SCR) is used at the site. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Pairing" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements and check procedures. *****For this check: Set IT Policy rule "Disable Headset Profile" (Bluetooth policy group) to "Yes" for non-headset IT policies. Set IT Policy rule "Disable Headset Profile" (Bluetooth policy group) to "No" for headset IT policies. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Headset Profile" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements and check procedures. *****For this check: Set IT Policy rule "Disable Handsfree Profile" (Bluetooth policy group) to "Yes" for non-headset IT policies. Set IT Policy rule "Disable Handsfree Profile" (Bluetooth policy group) to "No" for headset IT policies. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Handsfree Profile" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Serial Port Profile" (Bluetooth policy group) to "Yes" or "No", depending on if the Bluetooth Smart Card Reader is used at the site. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Serial Port Profile" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR4050-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Discoverable Mode" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Discoverable Mode" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Address Book Transfer" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Address Book Transfer" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Desktop Connectivity" (Bluetooth policy group) to "Yes" or "No", depending on if the Bluetooth Smart Card Reader (SCR) is used at the site and approved to connect to site PCs. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Desktop Connectivity" (Bluetooth policy group) is set as required. If set to "No", verify that the ISSO or ISSM has approved the use of BlackBerry smart card readers with site PCs. If set to "Yes", there is no finding. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Wireless Bypass" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Wireless Bypass" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Require Password for Enabling Bluetooth Support" to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Require Password for Enabling Bluetooth Support" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Require Password for Discoverable Mode" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V000354). *****Verify IT Policy rule "Require Password for Discoverable Mode" (Bluetooth policy group) is set as required. If not set as required, this is finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Require Encryption" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Require Encryption" (Bluetooth policy group) is set as required. If not set as required, this is finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable File Transfer" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable File Transfer" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Require LED Connection Indicator" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Require LED Connection Indicator" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Dial-Up Networking" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Dial-Up Networking" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Force CHAP Authentication Bluetooth Link" (Bluetooth policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Force CHAP Authentication Bluetooth Link" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Advanced Audio Distribution Profile" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Advanced Audio Distribution Profile" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Audio/Video Remote Control Profile" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Audio/Video Remote Control Profile" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Limit Discoverable Time" (Bluetooth policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Limit Discoverable Time" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable SIM Access Profile" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable SIM Access Profile" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Disable Revoked Certificate Use" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Revoked Certificate Use" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Disable Key Store Low Security" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Key Store Low Security" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Certificate Status Cache Timeout" (Security policy group) to "7". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Certificate Status Cache Timeout" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Disable Invalid Certificate Use" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Invalid Certificate Use" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Disable Weak Certificate Use" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V000354). *****Verify IT Policy rule "Disable Weak Certificate Use" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Certificate Status Maximum Expiry Time" (Security policy group) to "168 or less". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Certificate Status Maximum Expiry Time" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Disable Unverified CRLs" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Unverified CRLs" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "S/MIME Minimum Strong RSA Key Length" (S/MIME Application policy group) to "1024". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "S/MIME Minimum Strong RSA Key Length" (S/MIME Application policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "S/MIME Minimum Strong DH Key Length" (S/MIME Application policy group) to "1024". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "S/MIME Minimum Strong DH Key Length" (S/MIME Application policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "S/MIME Minimum Strong ECC Key Length" (S/MIME Application policy group) to "163". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "S/MIME Minimum Strong ECC Key Length" (S/MIME Application policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "S/MIME Allowed Content Ciphers" (S/MIME Application policy group) to "Check the following: 0 (AES-256 bit) 1 (AES-192 bit) 2 (AES-128 bit) 5 (Triple DES)" Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "S/MIME Allowed Content Ciphers" (S/MIME Application policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "S/MIME Minimum Strong DSA Key Length" (S/MIME Application policy group) to "1024". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "S/MIME Minimum Strong DSA Key Length" (S/MIME Application policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Entrust Messaging Server (EMS) Email Address" (S/MIME Application policy group) to "<blank>". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Entrust Messaging Server (EMS) Email Address" (S/MIME Application policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "S/MIME Allowed Encryption Types" (S/MIME Application policy group) to "Certificate based-only". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "S/MIME Allowed Encryption Types" (S/MIME Application policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Allow Public Yahoo! Messenger Services" (Service Exclusivity policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow Public Yahoo! Messenger Services" (Service Exclusivity policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule “Allow Public AIM Services” (Service Exclusivity group) to “No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Allow Public AIM Services” (Service Exclusivity policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Allow Public ICQ Services" (Service Exclusivity policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow Public ICQ Services" (Service Exclusivity policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: ***** For this check, set IT Policy rule "Allow Public IM Services" (Service Exclusivity policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow Public IM Services" (Service Exclusivity policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, Set IT Policy rule "Allow Public Google Talk Services" (Service Exclusivity policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow Public Google Talk Services" (Service Exclusivity policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Allow Public WLM Services" (Service Exclusivity policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow Public WLM Services" (Service Exclusivity policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Maximum Bluetooth Range" (BlackBerry SCR policy group) to "50% or less" Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1100-01 (V0003545). *****Verify IT Policy rule "Maximum Bluetooth Range" (BlackBerry SCR policy group) is set as required. Note: The correct setting can also be verified on the handheld: See "Reader Setting – Bluetooth Range" in Table 5, BlackBerry STIG Configuration Tables. Verifying the correct setting on the BES is the preferred procedure. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Maximum PC Disconnect Timeout" (BlackBerry Smart Card Reader policy group) to "0" or "<blank>." Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Maximum PC Disconnect Timeout" (BlackBerry Smart Card Reader policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Maximum Number of PC Pairings" (BlackBerry Smart Card Reader policy group) to "0" or "1" depending on if SCR connections to PCs are authorized. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1100-01 (V0003545). *****Verify IT Policy rule "Maximum Number of PC Pairings" (BlackBerry Smart Card Reader policy group) is set as required. Note: The correct setting can also be verified on the handheld: See "Reader Setting – Bluetooth Range" in Table 5, BlackBerry STIG Configuration Tables. Verifying the correct setting on the BES is the preferred procedure. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Allow IBS Browser" (Browser policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow IBS Browser" (Browser policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Allow Other Browser Services" (Services Exclusivity policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow Other Browser Services" (Services Exclusivity policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Users must be forced to install critical software updates. *****For this check, set IT Policy rule "Force Load Count" (Desktop-Only policy group) to "1" or "2". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Force Load Count" (Desktop-Only policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Users must be forced to install critical software updates and be notified when a software update is available. *****For this check, a notification message will be added to the IT Policy rule "Force Load Message" (Desktop-Only policy group). See the BlackBerry STIG Overview for an example. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Force Load Message" (Desktop-Only policy group) is set as required. If not set as required, this is not a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: If used, "Owner Name" must not identify a BlackBerry as a DoD BlackBerry. *****For this check, set IT Policy rule "Set Owner Name" (Common policy group) as follows: Leave blank or follow guidance in comment listed in the BlackBerry STIG Overview. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Set Owner Name" (Common policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: A timeout must be set up for the BlackBerry keystore password of 60 or less. 15 is recommended. *****For this check, set IT Policy rule "Keystore Password Maximum Timeout" (Security policy group) to 60 or less. 15 is recommended. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Keystore Password Maximum Timeout" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Split-pipe Connections are not allowed on DoD BlackBerrys. *****For this check, set IT Policy rule "Allow Split-Pipe connections" (Security policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow Split-Pipe Connections" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: BlackBerry FIPS level must be set to Level 1. *****For this check, set IT Policy rule "FIPS Level" (Security policy group) to "1 (FIPS 140-2 Level 1)." Check Procedures: This is a BES IT Policy check. Recommend that all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "FIPS Level" (Security policy group) is set as required. Note: This rule is obsolete in BlackBerry® Enterprise Server versions 4.1 SP3 and later and BlackBerry® Device Software versions 4.2.1and later. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: The BlackBerry keystore security level must be set to Medium or higher. *****For this check, set IT Policy rule "Minimal Signing Key Store Security Level" (Security policy group) to "Medium Security or High Security". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Minimal Signing Key Store Security Level" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: The BlackBerry keystore security level encryption key must be set to Medium or higher. *****For this check, set IT Policy rule "Minimal Encryption Key Store Security Level" (Security policy group) to "Medium Security or High Security". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Minimal Encryption Key Store Security Level" (Security policy group) is set as required. If not set as required, this is a finging.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: BlackBerry Master keys must be stored on the BlackBerry in encrypted form. *****For this check, set IT Policy rule "Force Content Protection of Master Keys" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Force Content Protection of Master Keys" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: The BlackBerry microphone indicator light must be on when the BlackBerry microphone is active. *****For this check, set IT Policy rule "Force LED Blinking When Microphone Is On" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Force LED Blinking When Microphone Is On" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Users must be required to enter their BlackBerry password prior to the download of applications. *****For this check, set IT Policy rule "Password Required for Application Download" (Security policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Password Required for Application Download" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: User access to Public Photo Sharing Applications will be blocked. *****For this check, set IT Policy rule "Disable Public Photo Sharing Applications" (Security group policy) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Public Photo Sharing Applications" (Security group policy) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: The use of transcoders is not permitted on DoD BlackBerrys. *****For this check, set IT Policy rule "Security Transcoder Cod File Hashes" (Security policy group) to <blank>. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Security Transcoder Cod File Hashes" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Only DoD-approved FIPS algorithms will be used. *****For this check, set IT Policy rule "Require FIPS Ciphers" (TLS policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Require FIPS Ciphers" (TLS policy group) is set as required. If not set as required, this is a finding.
Configure the BES IT policy rule "Require FIPS Ciphers" to Yes.
Detailed Policy Requirements: Only DoD-approved FIPS algorithms will be used. *****For this check, set IT Policy rule "Require FIPS Ciphers" (WTLS Application policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Require FIPS Ciphers" (WTLS Application policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: The use of Application Download Services will be blocked. *****For this check, set IT Policy rule "Allow Application Download Services" (Browser policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Allow Application Download Services" (Browser policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Only trusted connections will be allowed between the BlackBerry and the BlackBerry MDS Integration Service. *****For this check, set IT Policy rule "Verify BlackBerry MDS Integration Service Certificate" (BlackBerry MDS Integration Service policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Verify BlackBerry MDS Integration Service Certificate" (BlackBerry MDS Integration Service policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Access to Public BlackBerry MDS Integration Services will be blocked. *****For this check, set IT Policy rule "Disable Activation With Public BlackBerry MDS Integration Service" (BlackBerry MDS Integration Service policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Activation With Public BlackBerry MDS Integration Service" (BlackBerry MDS Integration Service policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Access to Web application stores will be blocked. *****For this check, set IT Policy rule "Disable Carrier Directory" (Application Center policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Carrier Directory" (Application Center policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Configuration management of the BlackBerry device software will be maintained. Only authorized software will be installed from a trusted source. Provisioning of the handheld will be completed under the control of the BlackBerry system administrator. *****For this check, set IT Policy rule "Desktop Allow Device Switch" (Desktop policy group) to "No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Desktop Allow Device Switch" (Desktop policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: File types with known vulnerabilities will not be downloaded via an IM connection. Specific banned file types are based on local policy (e.g., .exe, .bat.). *****For this check, set IT Policy rule "Disallow File Transfer Types" (Instant Messaging policy group) to "*" (to block all files) or specify specific file types to block based on local policy (e.g., .exe, .bat, mp3, .zip). Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disallow File Transfer Types" (Instant Messaging policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: File sharing services and applications will not be used on DoD BlackBerry systems, including BlackBerry Unite!. *****For this check, set IT Policy rule IT Policy rule "Disable BlackBerry Unite! Applications" (BlackBerry Unite! policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule IT Policy rule "Disable BlackBerry Unite! Applications" (BlackBerry Unite! policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: File sharing services and applications will not be used on DoD BlackBerry systems, including BlackBerry Unite!. *****For this check, set IT Policy rule IT Policy rule "Disable Download Manager" (BlackBerry Unite! policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule IT Policy rule "Disable Download Manager" (BlackBerry Unite! policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT policy “External File System Encryption Level” (Security policy group) to “4 - Encrypt to Device Key (including multi-media directories)". Check Procedures: This is an IT policy check. Recommend all checks related to BES IT Policies be reviewed using the procedures found in check WIR1400-01 (V0003545). *****Verify the IT policy assigned to each user has the IT Policy rule "External File System Encryption Level" (Security policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: User Initiated access to Public BlackBerry MDS Integration Services will be blocked. *****For this check, set IT Policy rule "Disable User Initiated Activation With Public BlackBerry MDS Integration Service" (BlackBerry MDS Integration Service policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable User initiated Activation With Public BlackBerry MDS Integration Service" (BlackBerry MDS Integration Service policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule “Allow BlackBerry Desktop Software Statistics” (Desktop policy group) to “No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Allow BlackBerry Desktop Software Statistics” (Desktop policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Only DoD approved applications will be used. *****For this check, set IT Policy rule “Allow Discovery by User” (MDS Integration Service policy group) to “No”. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy “Allow Discovery by User” (MDS Integration Service policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
*****For this check, set IT Policy rule "Encryption on On-Board Device Memory Media Files" (Security policy group) to "Required". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Encryption on On-Board Device Memory Media Files" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule “Allow Network Address Book Sync” (Service Exclusivity policy group) to “Disabled". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Allow Network Address Book Sync” (Service Exclusivity policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule “Allow User Feedback” (User Feedback policy group) to “No". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Allow User Feedback” (User Feedback policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: *****For this check, set IT Policy rule "Disable organizer data access for social networking applications" (Value-Added Applications policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable organizer data access for social networking applications" (Value-Added Applications policy group) is set as required.
Set IT Policy rule "Disable organizer data access for social networking applications" (Value-Added Applications policy group) to "Yes".
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Disable Message Access Profile" (Bluetooth policy group) to "Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Disable Message Access Profile" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Note: This check is Not Applicable if an Application White List has been set up on the BES and there are no findings for Application White List checks. Verify there are no findings for checks V-16341/WIR1310-01 and V-22042/WIR1310-02. Detailed Policy Requirements: Access to Web application stores will be blocked. *****For this check, set IT Policy rule “Application Restriction Rule” (BlackBerry App World policy group) to “Allow". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Application Restriction Rule” (BlackBerry App World policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Note: This check is Not Applicable if an Application White List has been set up on the BES and there are no findings for Application White List checks. Verify there are no findings for checks V-16341/WIR1310-01 and V-22042/WIR1310-02. Detailed Policy Requirements: Access to Web application stores will be blocked. *****For this check, set IT Policy rule “Category Restriction Rule” (BlackBerry App World policy group) to “Deny". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Category Restriction Rule” (BlackBerry App World policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: Access to Web application stores will be blocked. *****For this check, set IT Policy rule “Disable Application Purchasing” (BlackBerry App World policy group) to “Yes”. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Disable Application Purchasing” (BlackBerry App World policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
For this check, set IT Policy rule "Content Protection Usage" (Security policy group) to "Allowed". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Content Protection Usage" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: For this check, set IT Policy rule “Disable Browsing Of Remote Shared Folders” (Security policy group) to “Yes". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Disable Browsing Of Remote Shared Folders” (Security policy group) is set as required. Mark as a finding if not set as required.
Configure the IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements and check procedures. *****For this check, set IT Policy rule "Minimum Encryption Key Length" (Bluetooth policy group) to either "<blank>" or "16" for STIG IT Policies for no Bluetooth headsets or to "16" for STIG IT Policies for Bluetooth headsets. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Minimum Encryption Key Length" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule as specified in the "Checks" block.
Note: This check is Not Applicable if an Application White List has been set up on the BES and there are no findings for Application White List checks. Verify there are no findings for checks V-16341/WIR1310-01 and V-22042/WIR1310-02. Detailed Policy Requirements: Access to Web application stores will be blocked. *****For this check, set IT Policy rule “Application Restriction List” (BlackBerry App World policy group) to list all applications the AO has approved for download from BlackBerry App World.. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Application Restriction List” (BlackBerry App World policy group) is set as required. Mark as a finding if not set as required.
Configure the Application Restriction List IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: For this check, set IT Policy rule “BlackBerry Playbook Log Submission” (Companion Devices policy group) to "Disable". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). Verify "BlackBerry Playbook Log Submission” (Companion Devices policy group) is set as required. Mark as a finding if not set as required.
Configure the BlackBerry Playbook Log Submission IT Policy rule as specified in the "Checks" section.
This requirement can only be met via User Based Enforcement (UBE) at this time. Consult with the user to ensure there are no more than two sequential characters (for example, abc) or no more than two repeating characters (for example, 222) in the password. If the device password contains more than two sequential characters or more than two repeating characters, this is a finding.
Configure the device password so that there are no more than two sequential characters or no more than two repeating characters.
Detailed Policy Requirements: See Check WIR1405-01 (V0014198) for detailed policy requirements. *****For this check, set IT Policy rule "Human Interface Device Profile" (Bluetooth policy group) to "Disallow". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Human Interface Device Profile" (Bluetooth policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule Human Interface Device Profile as specified in the "Checks" block.
Detailed Policy Requirements: Set IT Policy rule "Disable Data Exchange for Mobile Hotspot Mode" (WLAN policy group) to "Yes". Check procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). Verify "Disable Data Exchange for Mobile Hotspot Mode" has been configured as required.
Configure the IT Policy rule Disable Data Exchange for Mobile Hotspot Mode as specified in the "Checks" block.
For this check, set IT Policy rule "Media Card Format on Device Wipe" (Security policy group) to "Required". Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule "Media Card Format on Device Wipe" (Security policy group) is set as required. If not set as required, this is a finding.
Configure the IT Policy rule Media Card Format on Device Wipe as specified in the "Checks" block.
Detailed Policy Requirements: For this check, set IT Policy rule “Application Installation Methods” (Security policy group) to: • Disallow Browser • Disallow Media Card • Disallow USB Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Application Installation Methods” (Wired Software Updates policy group) is set as required.
Configure the IT Policy rule Application Installation Methods as specified in the "Checks" block.
Detailed Policy Requirements: For this check, set IT Policy rule “Media Server” (Media Server policy group) to “Disallow”. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Media Server” (Media Server policy group) is set as required.
Configure the IT Policy rule Media Server as specified in the "Checks" block.
Detailed Policy Requirements: Access to Web application stores will be blocked. *****For this check, set IT Policy rule “Public Channel Downloads” (BlackBerry App World policy group) to “Disallow”. Check Procedures: This is a BES IT Policy check. Recommend all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Public Channel Downloads” (BlackBerry App World policy group) is set as required. Mark as a finding if not set as required.
Configure the Public Channel Downloads IT Policy rule as specified in the "Checks" block.
Detailed Policy Requirements: BlackBerry FIPS level must be set to Level 1. *****For this check, set IT Policy rule “Enforce FIPS Mode of Operation” (Security policy group) to “Yes.” Check Procedures: This is a BES IT Policy check. Recommend that all checks related to BES IT policies be reviewed using the procedure in Check WIR1400-01 (V0003545). *****Verify IT Policy rule “Enforce FIPS Mode of Operation” (Security policy group) is set as required. Mark as a finding if the IT Policy rule “Enforce FIPS Mode of Operation” (Security policy group) is not set to “Yes.” Note: This rule is applies to BlackBerry OS 7.x.
Configure the IT Policy rule Enforce FIPS Mode of Operation as specified in the "Checks" block.