The organization must have a CMD Personal Use Policy that specifies restrictions on the use of personal email.

From Mobile Policy Security Requirements Guide

Part of SRG-MPOL-056

Associated with: CCI-000082

SV-47290r1_rule The organization must have a CMD Personal Use Policy that specifies restrictions on the use of personal email.

Vulnerability discussion

Malware can be introduced to a DoD enclave via personally owned applications and personal web site accounts. In addition, sensitive DoD data could be exposed, altered, or exfiltrated by the same malware. The DoD component must publish a Personal Use Policy for DoD component managed or owned CMDs.The policy will provide information on allowed personal use of DoD component mobile devices, including devices approved for connection to DoD networks and processing of sensitive data; and for devices not approved for connection to DoD networks and processing of DoD data (for example, non-enterprise activated devices). The policy will be approved by the DAA based on a risk-based assessment. The assessment will consider costs to the Command that could result from additional wireless service charges from personal usage of the device.

Check content

Review the organization's policy to determine if it provides information on allowed personal use of DoD component mobile devices in respect to viewing or downloading personal email. The policy will be approved by the DAA based on a risk based assessment. If the organization does not have a policy on allowed personal use covering viewing or downloading personal email, this is a finding.

Fix text

Develop a Mobile Device Personal Use Policy which details the requirements for the operating system device to view or download personal email.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer