The organization must require that mobile devices used in facilities containing information systems processing, storing, or transmitting classified information, and the information stored on those devices, are subject to random reviews/inspections by organization defined security officials.

From Mobile Policy Security Requirements Guide

Part of SRG-MPOL-044

Associated with: CCI-001334

SV-47278r1_rule The organization must require that mobile devices used in facilities containing information systems processing, storing, or transmitting classified information, and the information stored on those devices, are subject to random reviews/inspections by organization defined security officials.

Vulnerability discussion

The organization's access control procedures and security policies establish the requirement to control the use of various mobile devices and connected or imbedded capabilities. These policies and procedures are ineffective if there is no process in place ensuring the policies and procedures are being followed. A process of randomly inspecting or reviewing the various mobile devices, to include connected or imbedded capabilities, can be effective in ensuring compliance with the organization’s mobile device policies and procedures.

Check content

Review the organization's access control and security policy, documentation for random inspections of mobile devices, and other relevant documents or records. Organizational personnel responsible for randomly reviewing/inspecting mobile devices and the information stored on those devices; and organizational personnel using mobile devices in facilities containing information systems processing, storing, or transmitting classified information, will be interviewed. Ensure the organization has established a requirement for mobile devices to be randomly reviewed/inspected to ensure compliance with the organization's access control policy regarding the use of mobile devices within its facilities. If a policy or procedure is not in place for random reviews or inspections, this is a finding.

Fix text

Develop and publish a requirement for mobile devices to be randomly reviewed/inspected for compliance with the organization's access control policy regarding the use of mobile devices within its facilities containing information systems processing, storing, or transmitting classified information, and the information stored on those devices.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer