CCI-000370
Manage configuration settings for organization-defined system components using organization-defined automated mechanisms.
Apple iOS/iPadOS 15 must [selection: wipe protected data, wipe sensitive data] upon unenrollment from MDM.
1 rule found Severity: Medium

1 rule found Severity: High

1 rule found Severity: Medium

Accounts for device management must be configured on the authentication server and not the network device itself, except for the account of last resort.
1 rule found Severity: Medium

Administrative accounts for device management must be configured on the authentication server and not the network device itself (except for the account of last resort).
1 rule found Severity: Medium

Google Android 12 must allow only the administrator (EMM) to install/remove DoD root and intermediate PKI certificates.
2 rules found Severity: Medium

The HYCU VM console and HYCU Web UI must be configured to use an authentication server for authenticating users prior to granting access to protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined requirements.
1 rule found Severity: High

1 rule found Severity: Medium

Administrative accounts for device management must be configured on the authentication server and not the MQ Appliance network device itself (except for the emergency administration account).
1 rule found Severity: Medium

Microsoft Android 11 must be configured to disable trust agents. Note: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.
1 rule found Severity: Medium

Microsoft Android 11 must allow the Administrator (EMM) to perform the following management function: Wipe Enterprise data.
2 rules found Severity: Medium

Microsoft Android 11 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates.
2 rules found Severity: Medium

Motorola Solutions Android 11 must be configured to disable trust agents. Note: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.
1 rule found Severity: Medium

Motorola Solutions Android 11 must allow only the Administrator (EMM) to perform the following management function: Enable/disable location services.
1 rule found Severity: Low

1 rule found Severity: Medium

Motorola Solutions Android 11 must allow only the administrator (EMM) to install/remove DoD root and intermediate PKI certificates.
1 rule found Severity: Medium

Microsoft Android 11 must be configured to disable trust agents. Note: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.
1 rule found Severity: Medium

Riverbed Optimization System (RiOS) must employ automated mechanisms to centrally manage authentication settings.
1 rule found Severity: Medium

Samsung Android must be configured to disable trust agents. NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product Common Criteria evaluation.
2 rules found Severity: Medium

Samsung Android must be configured to disable Face Recognition. NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product Common Criteria evaluation.
2 rules found Severity: Medium

Samsung Android Work Environment must allow only the Administrator (management tool) to perform the following management function: install/remove DoD root and intermediate PKI certificates.
2 rules found Severity: Medium

Accounts for device management must be configured on the authentication server and not on Symantec ProxySG itself, except for the account of last resort.
1 rule found Severity: Medium

The NSX-T Manager must integrate with either VMware Identity Manager (vIDM) or VMware Workspace ONE Access.
1 rule found Severity: High

Apple iOS/iPadOS 16 must not allow backup to remote systems (managed applications data stored in iCloud).
2 rules found Severity: Medium

Apple iOS/iPadOS 16 must implement the management setting: Encrypt iTunes backups/Encrypt local backup.
2 rules found Severity: Medium

2 rules found Severity: High

Apple iOS/iPadOS 16 must implement the management setting: not allow messages in an ActiveSync Exchange account to be forwarded or moved to other accounts in the Apple iOS/iPadOS 16 Mail app.
2 rules found Severity: Medium

2 rules found Severity: Low

2 rules found Severity: Low

2 rules found Severity: Medium

The network device must be configured to use an authentication server to authenticate users prior to granting administrative access.
5 rules found Severity: High

Zebra Android 11 must allow only the Administrator (EMM) to perform the following management function: Enable/disable location services.
1 rule found Severity: Low

Zebra Android 11 must allow only the administrator (EMM) to install/remove DoD root and intermediate PKI certificates.
1 rule found Severity: Medium

The BIG-IP appliance must be configured to employ automated mechanisms to centrally manage authentication settings.
1 rule found Severity: Medium

Apple iOS/iPadOS 16 must allow the Administrator (MDM) to perform the following management function: enable/disable VPN protection across the device and [selection: other methods].
1 rule found Severity: Low

Apple iOS/iPadOS 16 must not allow backup to remote systems (iCloud document and data synchronization).
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Apple iOS/iPadOS 16 must not allow backup to remote systems (iCloud Photo Sharing, also known as Shared Photo Streams).
1 rule found Severity: Medium

Apple iOS/iPadOS 16 must [selection: wipe protected data, wipe sensitive data] upon unenrollment from MDM.
1 rule found Severity: Medium

1 rule found Severity: Low

Apple iOS/iPadOS 16 must implement the management setting: Not allow automatic completion of Safari browser passcodes.
1 rule found Severity: Low

1 rule found Severity: Low

1 rule found Severity: Medium

Apple iOS/iPadOS 16 must implement the management setting: Not have any Family Members in Family Sharing.
1 rule found Severity: Low

1 rule found Severity: Medium

1 rule found Severity: Low

1 rule found Severity: Medium

1 rule found Severity: Medium

Apple iOS/iPadOS 16 must disable "Allow USB drive access in Files app" if the authorizing official (AO) has not approved the use of DoD-approved USB storage drives with iOS/iPadOS devices.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Cisco ASA must be configured to use at least two authentication servers to authenticate users prior to granting administrative access.
1 rule found Severity: High

The Cisco switch must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
2 rules found Severity: High

The Cisco router must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
2 rules found Severity: High

The Cisco ISE must be configured to use an external authentication server to authenticate administrators prior to granting administrative access.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to use at least two authentication servers to authenticate administrative users.
1 rule found Severity: High

The Google Android 14 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates (work profile).
1 rule found Severity: Medium

The Google Android 13 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates (work profile).
1 rule found Severity: Medium

The HPE Nimble must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.
1 rule found Severity: High

1 rule found Severity: High

The Juniper EX switch must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.
1 rule found Severity: High

The network device must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
1 rule found Severity: High

1 rule found Severity: High

The Riverbed NetProfiler must be configured to authenticate each administrator prior to authorizing privileges based on roles.
1 rule found Severity: High

The Riverbed NetProfiler must be configured to use an authentication server to authenticate users prior to granting administrative access.
1 rule found Severity: High

The TippingPoint SMS must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access and to enforce access restrictions.
1 rule found Severity: High

Apple iOS/iPadOS 18 must allow the administrator (MDM) to perform the following management function: enable/disable VPN protection across the device and [selection: on a per-app basis, on a per-group of applications processes basis].
1 rule found Severity: Low

1 rule found Severity: Medium

The Cisco switch must be configured to use at least two authentication servers to authenticate users prior to granting administrative access.
1 rule found Severity: High

The Cisco router must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
1 rule found Severity: High

The Dell OS10 Switch must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.
1 rule found Severity: High

The Dell OS10 Switch must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
1 rule found Severity: High

Forescout must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.
1 rule found Severity: Medium

The Google Android 13 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates.
2 rules found Severity: Medium

The Google Android 14 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates.
2 rules found Severity: Medium

The Google Android 15 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates.
2 rules found Severity: Medium

AOS must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
1 rule found Severity: High

The HYCU virtual appliance must be configured to use at least two authentication servers for authenticating users prior to granting administration access.
1 rule found Severity: High

The Juniper router must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
1 rule found Severity: High

The Juniper SRX Services Gateway must be configured to use an authentication server to centrally manage authentication and logon settings for remote and nonlocal access.
1 rule found Severity: Medium

Samsung Android's Work environment must allow only the Administrator (management tool) to perform the following management function: Install/remove DOD root and intermediate PKI certificates.
2 rules found Severity: Medium

Samsung Android must allow only the Administrator (management tool) to perform the following management function: Install/remove DOD root and intermediate PKI certificates.
1 rule found Severity: Medium

Samsung Android's Work profile must allow only the Administrator (management tool) to perform the following management function: Install/remove DOD root and intermediate PKI certificates.
1 rule found Severity: Medium

The NSX Manager must be configured to integrate with an identity provider that supports multifactor authentication (MFA).
1 rule found Severity: High

The Zebra Android 13 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates.
2 rules found Severity: Medium

Apple iOS/iPadOS 15 must provide the capability for the Administrator (MDM) to perform the following management function: enable/disable VPN protection across the device and [selection: other methods].
1 rule found Severity: Low

Apple iOS/iPadOS 16 must allow the administrator (MDM) to perform the following management function: enable/disable VPN protection across the device.
1 rule found Severity: Medium

1 rule found Severity: Medium
