From Mobile Policy Security Requirements Guide
Part of SRG-MPOL-017
Associated with: CCI-001439
Unauthorized wireless systems expose DoD networks to attack. The DAA and appropriate commanders must be aware of all wireless systems used at the site. DAAs should ensure a risk assessment is conducted for each system, including associated services and peripherals, before approving. The DAA should accept risks only when required to meet mission requirements.
Review the organization's documentation of the wireless system connected to a DoD network to verify DAA approval either by: a.) The accreditation documentation, which must show the wireless system as part of the network diagram or list the system/equipment as being part of the network. b.) DAA approval letter or other document, which must list the system or equipment and date its use is approved. The DAA approval letter or site security plan may be a general statement of approval rather than list each device; however, it does not need to be documented separately from other DAA approval documents for the site network, as long as the approval documents list the wireless system. Verify DAA approval for the type of device used, such as wireless connection services, peripherals, and applications. If wireless systems (including associated peripheral devices, operating system, applications, network/PC connection methods and services) exist and are not approved by the approval authority prior to installation and use for processing DoD information, this is a finding.
Obtain DAA approval, documented by memo or site security plan, prior to wireless systems connected to a DoD network being installed or utilized.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer