STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must be configured with the periodicity of the following commands to the agent of six hours or less: - query connectivity status - query the current version of the managed device firmware/software - query the current version of installed mobile applications - read audit logs kept by the managed device.

DISA Rule

SV-251419r1004746_rule

Vulnerability Number

V-251419

Group Title

SRG-APP-000472-UEM-000347

Rule Version

IMIC-11-010900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the MDM server with a periodicity for reachable events of six hours or less for the following commands to the agent:
- query connectivity status;
- query the current version of the MD firmware/software;
- query the current version of the hardware model of the device;
- query the current version of installed mobile applications;
-read audit logs kept by the MD.

Configure the sync interval for a device:
To configure the frequency for starting the synchronization process between a device in MobileIron Core:
1. In the Admin Portal, go to Policies & Config >> Policies.
2. Select the default sync policy.
3. Set Sync Interval to the number of minutes between synchronizations to be 360 minutes or less.
4. Click "Save".

Check Contents

Review the MDM server configuration settings and verify the server is configured with a periodicity for reachable events of six hours or less for the following commands to the agent:
- query connectivity status;
- query the current version of the MD firmware/software;
- query the current version of the hardware model of the device;
- query the current version of installed mobile applications;
- read audit logs kept by the MD.

Verify the sync interval for a device:
1. In the Admin Portal, go to Policies & Config >> Policies.
2. Select the default sync policy.
3. Verify that the Sync Interval is set to 360 minutes or less.

If the Sync interval is not set to 360 minutes or less, this is a finding.

Vulnerability Number

V-251419

Documentable

False

Rule Version

IMIC-11-010900

Severity Override Guidance

Review the MDM server configuration settings and verify the server is configured with a periodicity for reachable events of six hours or less for the following commands to the agent:
- query connectivity status;
- query the current version of the MD firmware/software;
- query the current version of the hardware model of the device;
- query the current version of installed mobile applications;
- read audit logs kept by the MD.

Verify the sync interval for a device:
1. In the Admin Portal, go to Policies & Config >> Policies.
2. Select the default sync policy.
3. Verify that the Sync Interval is set to 360 minutes or less.

If the Sync interval is not set to 360 minutes or less, this is a finding.

Check Content Reference

M

Target Key

5445