Skip to content

Unified Endpoint Management Agent Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The UEM Agent must perform the following functions: Import the certificates to be used for authentication of UEM Agent communications.

    It is critical that the UEM agent only use validated certificates for policy updates. Otherwise, there is no assurance that a malicious actor has not inserted itself in the process of packaging the...
    Rule Medium Severity
  • The UEM Agent must perform the following functions: -enroll in management -configure whether users can unenroll from management -configure periodicity of reachability events.

    Access control of mobile devices to DoD sensitive information or access to DoD networks must be controlled so that DoD data will not be compromised. The primary method of access control of mobile d...
    Rule Medium Severity
  • All UEM Agent cryptography supporting DoD functionality must be FIPS 140-2 validated.

    Unapproved cryptographic algorithms cannot be relied on to provide confidentiality or integrity, and DoD data could be compromised as a result. The most common vulnerabilities with cryptographic mo...
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules