STIGQter STIGQter: STIG Summary: BlackBerry CylancePROTECT Mobile for UEM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2024:

CylancePROTECT Mobile must be configured with the following compliance actions for integrity violations with BlackBerry Dynamics apps on iOS devices: -Prompt for compliance: Immediate enforcement action -Prevent the user from accessing BlackBerry Dynamics apps while the device is out of compliance.

DISA Rule

SV-257266r918382_rule

Vulnerability Number

V-257266

Group Title

SRG-APP-000516-AS-000237

Rule Version

BBCP-00-013200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the following compliance actions for iOS device integrity violations for BlackBerry Dynamics apps:
-Prompt for compliance: Immediate enforcement action.
-Prevent the user from accessing BlackBerry Dynamics apps while the device is out of compliance.

1. Log on to the BlackBerry UEM console.
2. In the management console on the menu bar, click Policies and profiles >> Compliance >> Compliance.
3. Create a new compliance profile or select and edit an existing compliance profile.
4. On the iOS tab in the BlackBerry Protect section, select the "App integrity failed" check box.
5. Configure the behavior prompt settings: Prompt for compliance: "Immediate enforcement action".
6. In the "Enforcement action for BlackBerry Dynamics apps" drop-down list, choose the following: "Do not allow BlackBerry Dynamics apps to run".
7. Click "Add" or "Save".
8. Assign the profile to users and groups.

Check Contents

Verify the following compliance actions for BlackBerry Dynamics apps are configured when there is an iOS device integrity violation:
-Prompt for compliance: Immediate enforcement action.
-Prevent the user from accessing BlackBerry Dynamics apps while the device is out of compliance.

1. Log on to the BlackBerry UEM console.
2. In the management console on the menu bar, click Policies and profiles >> Compliance >> Compliance.
3. View the appropriate compliance profile (have the site system administrator identify the profile).
4. On the iOS tab in the BlackBerry Protect section, verify the "App integrity failed" check box is selected.
5. In the "Prompt for compliance" drop-down list verify "Immediate enforcement action" is selected
6. In the "Enforcement action for BlackBerry Dynamics apps" drop-down list, verify "Do not allow BlackBerry Dynamics apps to run" is selected.

If required compliance actions for integrity violations for BlackBerry Dynamics apps on iOS devices are not enabled, this is a finding.

Vulnerability Number

V-257266

Documentable

False

Rule Version

BBCP-00-013200

Severity Override Guidance

Verify the following compliance actions for BlackBerry Dynamics apps are configured when there is an iOS device integrity violation:
-Prompt for compliance: Immediate enforcement action.
-Prevent the user from accessing BlackBerry Dynamics apps while the device is out of compliance.

1. Log on to the BlackBerry UEM console.
2. In the management console on the menu bar, click Policies and profiles >> Compliance >> Compliance.
3. View the appropriate compliance profile (have the site system administrator identify the profile).
4. On the iOS tab in the BlackBerry Protect section, verify the "App integrity failed" check box is selected.
5. In the "Prompt for compliance" drop-down list verify "Immediate enforcement action" is selected
6. In the "Enforcement action for BlackBerry Dynamics apps" drop-down list, verify "Do not allow BlackBerry Dynamics apps to run" is selected.

If required compliance actions for integrity violations for BlackBerry Dynamics apps on iOS devices are not enabled, this is a finding.

Check Content Reference

M

Target Key

5544