UCF STIG Viewer Logo

The mobile operating system must protect the confidentiality of the provisioning data downloaded to the handheld device during a trusted over-the-air (OTA) provisioning session.


Finding ID Version Rule ID IA Controls Severity
V-32701 WIR-MOS-iOS-65-03 SV-43047r1_rule ECWN-1 Medium
Provisioning data may be sensitive and therefore must be adequately protected. An adversary within the general proximity of the mobile device can eavesdrop on OTA transactions, making them particularly vulnerable to attack if confidentiality protections are not in place. Proper use of cryptography provides strong assurance that provisioning data is protected against confidentiality attacks.
Apple iOS 5 Security Technical Implementation Guide (STIG) 2012-07-20


Check Text ( C-41064r1_chk )
Review system documentation and operating system configuration to determine if there is appropriate cryptography protecting the confidentiality of OTA provisioning. If the provisioning data is not protected by cryptographic means during an OTA provisioning procedure, this is a finding.
Fix Text (F-36599r1_fix)
Configure the operating system to use cryptography providing confidentiality for provisioning downloads.