STIGQter STIGQter: STIG Summary: Samsung SDS EMM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 27 Jul 2022:

Authentication of MDM platform accounts must be configured so they are implemented via an enterprise directory service.

DISA Rule

SV-245526r744388_rule

Vulnerability Number

V-245526

Group Title

PP-MDM-414003

Rule Version

SSDS-00-000720

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure SDS EMM to leverage the MDM platform administrator accounts and groups for user (system administrator) identification and CAC authentication.

Complete the following procedures:
1. Follow necessary setup steps for Admin Registration, Tomcat Server Settings, Directory Settings found on the top of page 536 of the Samsung SDS EMM 2.2.5.3 Administrator Guide.
(Refer to the "CAC Sign-In" section of the Appendix of the Samsung SDS EMM 2.2.5.3 Administrator Guide for detailed setting procedures in the CAC authentication/Directory Services environment for the SDS EMM)
2. Enable CAC Sign-In by the following procedure:
- Log in to the SDS EMM console.
- Go to Settings >> Server >> Configuration.
- Click "CAC Sign-In".
- Configure the "CAC Sign-In Settings", Port", and "Directory Service Name".
- Click Save.

Check Contents

Verify SDS EMM is leveraging the MDM platform administrator accounts and groups for user (system administrator) identification and CAC authentication.

Use one of the following methods:

Method 1:
- Attempt to log on to the SDS EMM console using a CAC.
- Verify CAC log on was successful.

Method 2:
- Log in to the SDS EMM console.
- Go to Settings >> Server >> Configuration.
- Click "CAC Sign-In".
- Verify CAC Sign-In has been set up.

If SDS EMM is not leveraging the MDM platform administrator accounts and groups for user (system administrator) identification and CAC authentication, this is a finding.

Vulnerability Number

V-245526

Documentable

False

Rule Version

SSDS-00-000720

Severity Override Guidance

Verify SDS EMM is leveraging the MDM platform administrator accounts and groups for user (system administrator) identification and CAC authentication.

Use one of the following methods:

Method 1:
- Attempt to log on to the SDS EMM console using a CAC.
- Verify CAC log on was successful.

Method 2:
- Log in to the SDS EMM console.
- Go to Settings >> Server >> Configuration.
- Click "CAC Sign-In".
- Verify CAC Sign-In has been set up.

If SDS EMM is not leveraging the MDM platform administrator accounts and groups for user (system administrator) identification and CAC authentication, this is a finding.

Check Content Reference

M

Target Key

4216