BlackBerry PlayBook OS V2.1 Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- PB21-00-000100
- Vuln IDs
-
- V-38703
- Rule IDs
-
- SV-50508r1_rule
Checks: C-46271r1_chk
Navigate to "Options -> BlackBerry Balance" and select the Pencil icon. Ensure "Remove Password" button exists and is greyed out. Otherwise, this is a finding.
Fix: F-43657r1_fix
On BlackBerry Device Service, set "Password Required for Work Space" IT Policy rule to "Yes".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- PB21-00-000110
- Vuln IDs
-
- V-38704
- Rule IDs
-
- SV-50509r1_rule
Checks: C-46272r1_chk
Navigate to "Options -> Security ->Password" and ensure "Enable Password" is set to "ON". Otherwise, this is a finding.
Fix: F-43658r1_fix
Navigate to "Options -> Security ->Password" and set "Enable Password" is set to "ON". Create a 4 digit passcode for the device lock.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- PB21-00-000120
- Vuln IDs
-
- V-38705
- Rule IDs
-
- SV-50510r1_rule
Checks: C-46273r1_chk
On BlackBerry Device Service, ensure "Security Timeout" IT Policy rule is set to "15 minutes". Otherwise, this is a finding.
Fix: F-43659r1_fix
On BlackBerry Device Service, set "Security Timeout" IT Policy rule to "15 minutes".
- RMF Control
- AU-8
- Severity
- L
- CCI
- CCI-000160
- Version
- PB21-00-000130
- Vuln IDs
-
- V-38706
- Rule IDs
-
- SV-50511r1_rule
Checks: C-46274r1_chk
Navigate to "Options -> Date & Time" and ensure "Set Date and Time Automatically" is set to "ON". Otherwise, this is a finding.
Fix: F-43660r1_fix
Navigate to "Options -> Date & Time" and set "Set Date and Time Automatically" is to "ON".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000192
- Version
- PB21-00-000140
- Vuln IDs
-
- V-38707
- Rule IDs
-
- SV-50512r1_rule
Checks: C-46275r1_chk
1. Navigate to "Options -> BlackBerry Balance". 2. Select the Pencil icon. 3. Select "Change Password". 4. Select "Password Rules". 5. Verify the dialog states: "Password must contain at least one uppercase letter". Otherwise, this is a finding.
Fix: F-43661r1_fix
On BlackBerry Device Service: Set "Minimum Password Complexity" IT Policy rule to: "At least 1 uppercase letter, 1 lowercase letter, 1 number, and 1 special character".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000193
- Version
- PB21-00-000150
- Vuln IDs
-
- V-38708
- Rule IDs
-
- SV-50513r1_rule
Checks: C-46276r1_chk
1. Navigate to "Options -> BlackBerry Balance". 2. Select the Pencil icon. 3. Select "Change Password". 4. Select "Password Rules". 5. Verify the dialog states: "Password must contain at least one lowercase letter". Otherwise, this is a finding.
Fix: F-43662r1_fix
On BlackBerry Device Service: Set "Minimum Password Complexity" IT Policy rule to: "At least 1 uppercase letter, 1 lowercase letter, 1 number, and 1 special character".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000194
- Version
- PB21-00-000160
- Vuln IDs
-
- V-38709
- Rule IDs
-
- SV-50514r1_rule
Checks: C-46277r1_chk
1. Navigate to "Options -> BlackBerry Balance". 2. Select the Pencil icon. 3. Select "Change Password". 4. Select "Password Rules". 5. Verify the dialog states: "Password must contain at least one number". Otherwise, this is a finding.
Fix: F-43663r1_fix
On BlackBerry Device Service: Set "Minimum Password Complexity" IT Policy rule to: "At least 1 uppercase letter, 1 lowercase letter, 1 number, and 1 special character".
- RMF Control
- IA-5
- Severity
- L
- CCI
- CCI-000199
- Version
- PB21-00-000170
- Vuln IDs
-
- V-38710
- Rule IDs
-
- SV-50515r1_rule
Checks: C-46278r1_chk
If the local command determines that there is not a need for password rotation based on the expected operational use of the device, this requirement does not apply. On BlackBerry Device Service: "Maximum Password Age" IT Policy rule must be set to 60 or less. Otherwise, this is a finding
Fix: F-43664r1_fix
On BlackBerry Device Service: Set "Maximum Password Age" IT Policy rule to: 60.
- RMF Control
- IA-5
- Severity
- L
- CCI
- CCI-000200
- Version
- PB21-00-000180
- Vuln IDs
-
- V-38711
- Rule IDs
-
- SV-50516r1_rule
Checks: C-46279r1_chk
If the local command determines that there is not a need for password rotation based on the expected operational use of the device, this requirement does not apply. On BlackBerry Device Service: "Maximum Password History" IT Policy rule must be set to 5 or more. Otherwise, this is a finding.
Fix: F-43665r1_fix
On BlackBerry Device Service: Set "Maximum Password History" IT Policy rule to: 5.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- PB21-00-000190
- Vuln IDs
-
- V-38712
- Rule IDs
-
- SV-50517r1_rule
Checks: C-46280r1_chk
1. Navigate to "Options -> BlackBerry Balance". 2. Select the Pencil icon. 3. Select "Change Password". 4. Select "Password Rules". 5. Verify the dialog states: "Password must be at least 8 characters long". Otherwise, this is a finding.
Fix: F-43666r1_fix
On BlackBerry Device Service: Set "Minimum Password Length" IT Policy rule to: 8.
- RMF Control
- IA-5
- Severity
- L
- CCI
- CCI-000205
- Version
- PB21-00-000200
- Vuln IDs
-
- V-38737
- Rule IDs
-
- SV-50542r1_rule
Checks: C-46282r1_chk
Lock the device by "Battery icon -> Lock". Unlock the device using the device lock password. If the unlock password is less than 4 characters, this is a finding.
Fix: F-43692r1_fix
Navigate to "Options -> Security -> Password -> Change Password". Input the old password under "Old Password". Under "New Password" and "Confirm Password" fields, input a new password that is greater or equal to 4 characters.
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-000381
- Version
- PB21-00-000210
- Vuln IDs
-
- V-38738
- Rule IDs
-
- SV-50543r1_rule
Checks: C-46283r1_chk
Navigate to "Options -> Security -> Application Permissions" and select each application listed, and ensure only DoD authorized permissions (Files, GPS Location, Camera, etc.) for this application is set to "Allowed" or "Prompt", with non-authorized permissions set to "Denied". Otherwise, this is a finding.
Fix: F-43693r1_fix
Navigate to "Options -> Security -> Application Permissions" and select each application listed, and set only DoD authorized permissions (Files, GPS Location, Camera, etc.) for this application to "Allowed" or "Prompt", with non-authorized permissions set to "Denied".
- RMF Control
- SA-7
- Severity
- H
- CCI
- CCI-000663
- Version
- PB21-00-000220
- Vuln IDs
-
- V-38739
- Rule IDs
-
- SV-50544r1_rule
Checks: C-46284r1_chk
Navigate to "Options ->Security -> Development Mode" and ensure "Use Development Mode" is set to "OFF" and greyed out. Otherwise, this is a finding.
Fix: F-43694r1_fix
On BlackBerry Device Service: Set "Restrict Development Mode" IT Policy rule to "Yes".
- RMF Control
- SA-7
- Severity
- M
- CCI
- CCI-000663
- Version
- PB21-00-000230
- Vuln IDs
-
- V-38740
- Rule IDs
-
- SV-50545r1_rule
Checks: C-46285r1_chk
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3. Review the applications listed under "BlackBerry World Applications". If any applications are listed, this is a finding.
Fix: F-43695r1_fix
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3. Delete all applications under "BlackBerry World Applications".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000780
- Version
- PB21-00-000240
- Vuln IDs
-
- V-38741
- Rule IDs
-
- SV-50546r1_rule
Checks: C-46286r1_chk
Navigate to "Options -> Wi-Fi -> Saved Networks" and select a Wi-Fi profile used to connect to DoD WLAN. Ensure "Security Type" is set to "WPA Enterprise" or "WPA2 Enterprise" and "Security Sub Type" (EAP security method) is set to "TLS". These options should be greyed out. Otherwise, this is a finding.
Fix: F-43696r1_fix
On BlackBerry Device Service: Select the affected Wi-Fi Profile, and set "Security Type" to "WPA Enterprise" or "WPA2 Enterprise" and "Security Sub Type" to "TLS".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000780
- Version
- PB21-00-000250
- Vuln IDs
-
- V-38742
- Rule IDs
-
- SV-50547r1_rule
Checks: C-46287r1_chk
1. Navigate to "Options -> Security -> VPN". 2. Select the enterprise VPN Profile (Work VPN Profiles have a briefcase icon on the right hand side). 3. Verify "Authentication Type" is set to a bidirectional cryptographically based authentication, and greyed out. Otherwise, this is a finding.
Fix: F-43697r1_fix
On BlackBerry Device Service: Create a VPN Profile with approved "Authentication Type" configured, and associate VPN Profile with IT Policy for the affected device.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000780
- Version
- PB21-00-000260
- Vuln IDs
-
- V-38743
- Rule IDs
-
- SV-50548r1_rule
Checks: C-46288r1_chk
Navigate to "Options -> Security -> VPN -> <VPN Profile>" and ensure "Authentication Type" is set to "PKI" or "XAUTH-PKI", and greyed out. Otherwise, this is a finding.
Fix: F-43698r1_fix
On BlackBerry Device Service, set select the applicable VPN Profile and set "Authentication Type" is to "PKI" or "XAUTH-PKI".
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001130
- Version
- PB21-00-000270
- Vuln IDs
-
- V-38744
- Rule IDs
-
- SV-50549r1_rule
Checks: C-46289r1_chk
Navigate to "Options -> Security -> VPN". Select each VPN Profile used to connect to a DoD network, and ensure "Gateway Type" is set to a type which supports and utilizes IPSec and SSL/TLS and greyed out. Otherwise, this is a finding.
Fix: F-43699r1_fix
On BDS, select the affected VPN Profile for Edit, and set "Gateway Type" is to a type which supports and utilizes IPSec and SSL/TLS.
- RMF Control
- SC-15
- Severity
- M
- CCI
- CCI-001154
- Version
- PB21-00-000290
- Vuln IDs
-
- V-38746
- Rule IDs
-
- SV-50551r1_rule
Checks: C-46291r1_chk
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3. Review the listed IM systems. If any unauthorized IM systems are listed, this is a finding.
Fix: F-43701r1_fix
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3. Delete the unauthorized IM system application.
- RMF Control
- SC-17
- Severity
- H
- CCI
- CCI-001159
- Version
- PB21-00-000310
- Vuln IDs
-
- V-38748
- Rule IDs
-
- SV-50553r1_rule
Checks: C-46293r1_chk
Navigate to "Options -> Security -> Certificates". Select each certificate listed under "All Certificates". In "Certificate Details", ensure "Issued By" states appropriate DoD certificate authority, or the certificate itself has been approved by DoD. Otherwise, this is a finding.
Fix: F-43703r1_fix
On BlackBerry Device Service Server: Remove the corresponding .pem file from <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www> folder.
- RMF Control
- SC-17
- Severity
- M
- CCI
- CCI-001159
- Version
- PB21-00-000320
- Vuln IDs
-
- V-38749
- Rule IDs
-
- SV-50554r1_rule
Checks: C-46294r1_chk
Navigate to "Options -> Security -> Certificates". Select each certificate listed under "All Certificates". In "Certificate Details", ensure "Issued By" states appropriate DoD certificate authority, or the certificate itself has been approved by DoD. Otherwise, this is a finding.
Fix: F-43704r1_fix
On BlackBerry Device Service Server: Remove the corresponding .pem file from <drive>:\<shared_network_folder>\Shared\Certificates\<ENTERPRISE/VPN/WIFI/www> folder.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-001265
- Version
- PB21-00-000330
- Vuln IDs
-
- V-38750
- Rule IDs
-
- SV-50555r1_rule
Checks: C-46295r1_chk
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3. Review the listed browser applications. If any unauthorized browser applications are listed, this is a finding.
Fix: F-43705r1_fix
On BlackBerry Device Service: 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand "Software -> Applications". 2. Click "Manage applications". 3. Delete the unauthorized browser application.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- PB21-00-000350
- Vuln IDs
-
- V-38752
- Rule IDs
-
- SV-50557r1_rule
Checks: C-46297r1_chk
1. Navigate to "Options -> About -> BlackBerry Balance". 2. Review the "IT Policy Name" assigned to the user. If different from the BDS policy, this is a finding.
Fix: F-43707r1_fix
On BlackBerry Device Service: 1. Navigate to "BlackBerry solution management -> User -> Manage users -> <affected user's device PIN>". 2. Select "Resend IT Policy to a device".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- PB21-00-000360
- Vuln IDs
-
- V-38753
- Rule IDs
-
- SV-50558r1_rule
Checks: C-46298r1_chk
To verify IT Policy: 1. Navigate to "Options -> Accounts". 2. Verify that all required work accounts (with a briefcase icon) are present. Otherwise, this is a finding.
Fix: F-43708r1_fix
On BlackBerry Device Service: 1. Navigate to "BlackBerry solution management -> Profiles -> Manage email profiles". 2. Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create email profiles". 3. Assign all required email profiles to the affected user, or a group containing the user.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- PB21-00-000370
- Vuln IDs
-
- V-38754
- Rule IDs
-
- SV-50559r1_rule
Checks: C-46299r1_chk
1. Navigate to "Options -> Wi-Fi -> Saved Networks". 2. Verify that all required work Wi-Fi profiles (with a briefcase icon) are present. Otherwise, this is a finding.
Fix: F-43709r1_fix
On BlackBerry Device Service: 1. Navigate to "BlackBerry solution management -> Profiles -> Manage Wi-Fi Profiles". 2. Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create Wi-Fi Profiles". 3. Assign all required Wi-Fi profiles to the affected user, or a group containing the user.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- PB21-00-000380
- Vuln IDs
-
- V-38755
- Rule IDs
-
- SV-50560r1_rule
Checks: C-46300r1_chk
1. Navigate to "Options -> Security -> VPN". 2. Verify that all required work VPN profiles (with a briefcase icon) are present. Otherwise, this is a finding.
Fix: F-43710r1_fix
On BlackBerry Device Service: 1. Navigate to "BlackBerry solution management -> Profiles -> Manage VPN Profiles". 2. Ensure all required profiles are listed. If not, create necessary profiles by navigating to "BlackBerry solution management -> Profiles -> Create VPN Profiles". 3. Assign all required VPN profiles to the affected user, or a group containing the user.
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001200
- Version
- PB21-00-000390
- Vuln IDs
-
- V-38756
- Rule IDs
-
- SV-50561r1_rule
Checks: C-46301r1_chk
Navigate to "Options -> Security -> Encryption" and ensure it states: "Personal data and files are encrypted" and cannot be disabled. Otherwise, this is a finding.
Fix: F-43711r1_fix
On BlackBerry Device Service, set "Personal Space Data Encryption" IT Policy rule to "Yes".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000066
- Version
- PB21-00-000400
- Vuln IDs
-
- V-38757
- Rule IDs
-
- SV-50562r1_rule
Checks: C-46302r1_chk
Navigate to "Options -> Storage & Sharing" and ensure "Wi-Fi Sharing" is set to "OFF". Otherwise, this is a finding.
Fix: F-43712r1_fix
Navigate to "Options -> Storage & Sharing" and set "Wi-Fi Sharing" to "OFF".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- PB21-00-000410
- Vuln IDs
-
- V-38758
- Rule IDs
-
- SV-50563r1_rule
Checks: C-46303r1_chk
1. Navigate to "Options -> BlackBerry Balance". 2. Select the Pencil icon. 3. Verify the "Remove Password" button is greyed out. Otherwise, this is a finding.
Fix: F-43713r1_fix
On BlackBerry Device Service: Set "Password Required for Work Space" IT Policy rule to: "Yes".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- PB21-00-000420
- Vuln IDs
-
- V-38759
- Rule IDs
-
- SV-50564r1_rule
Checks: C-46304r1_chk
1. Navigate to "Options -> Security -> Password". 2. Verify "Enable Password" is set to "ON". Otherwise, this is a finding.
Fix: F-43714r1_fix
1. Navigate to "Options -> Security -> Password". 2. Set "Enable Password" is set to "ON". 3. Create a 4 digit passcode for the device.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- PB21-00-000000
- Vuln IDs
-
- V-53891
- Rule IDs
-
- SV-68129r1_rule
Checks: C-54741r2_chk
Manufacturer support for BlackBerry Playbook tablets ended April 2014. If BlackBerry Playbook tablets are in use, this is a finding.
Fix: F-58741r2_fix
Replace the BlackBerry PlayBook with an approved device.