Skip to content

Unified Endpoint Management Agent Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000176

    <GroupDescription></GroupDescription>
    Group
  • The UEM Agent must use managed endpoint device key storage for all persistent secret and private keys.

    &lt;VulnDiscussion&gt;If validated secure storage locations are not used for keys, they could be compromised. Satisfies: FCS_STG_EXT.1(2)&lt;/Vuln...
    Rule Medium Severity
  • SRG-APP-000358

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000358

    <GroupDescription></GroupDescription>
    Group
  • The UEM Agent must be configured to enable the following function: transfer managed endpoint device audit logs read by the UEM Agent to an UEM server or third-party audit management server.

    &lt;VulnDiscussion&gt;Audit logs and alerts enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help i...
    Rule Medium Severity
  • The UEM Agent must be configured to perform one of the following actions upon an attempt to unenroll the mobile device from management: -prevent the unenrollment from occurring -wipe the device to factory default settings -wipe the work profile with all associated applications and data.

    &lt;VulnDiscussion&gt;Access control of mobile devices to DoD sensitive information or access to DoD networks must be controlled so that DoD data w...
    Rule Medium Severity
  • SRG-APP-000555

    <GroupDescription></GroupDescription>
    Group
  • All UEM Agent cryptography supporting DoD functionality must be FIPS 140-2 validated.

    &lt;VulnDiscussion&gt;Unapproved cryptographic algorithms cannot be relied on to provide confidentiality or integrity, and DoD data could be compro...
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules