UCF STIG Viewer Logo

The mobile device Wi-Fi radio must be disabled as the default setting and is enabled only when Wi-Fi connectivity is required.


Overview

Finding ID Version Rule ID IA Controls Severity
V-25020 WIR-MOS-iOS-041 SV-34931r2_rule ECWN-1 Low
Description
The Wi-Fi radio can be used by a hacker to connect to the smartphone without the knowledge of the user. Sensitive DoD data could be exposed and the hacker could use the device to attack the enclave.
STIG Date
Apple iOS 5 Security Technical Implementation Guide (STIG) 2012-07-20

Details

Check Text ( C-31223r3_chk )
This is a User Based Enforcement (UBE) setting.

On a sample of site-managed iOS devices (pick 3-4 random devices), check that the Wi-Fi radio is turned off.

-Have the user turn on and log into the device.
-Go to Settings > Wi-Fi. Wi-Fi should be turned off.

Mark as a finding if configuration is not set as required.
Fix Text (F-27691r2_fix)
Train user to disable the smartphone Wi-Fi radio unless Wi-Fi connectivity is required.