UCF STIG Viewer Logo

The organizations physical security policy must state that CMDs with cameras must not be allowed in any SCIF or other areas where classified documents or information is stored, transmitted, or processed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35991 SRG-MPOL-073 SV-47307r1_rule High
Description
CMDs with embedded cameras can be used to photograph classified material and can be easily concealed. Classified information could be compromised. Photos may also be taken of the areas that would facilitate a subsequent physical security breach.
STIG Date
Mobile Policy Security Requirements Guide 2013-01-24

Details

Check Text ( C-44228r1_chk )
This requirement also applies to handheld barcode scanners equipped with imagers, unless the manufacturer certifies the raw image is only used for bar code processing and is not available to any other application.

Interview the Security Manager and review the following information:
- Site's physical security policy.
-Verify users are informed of this policy by reviewing user agreements, posted signs, or training material.
- Powering off, removing batteries, or blocking infrared (IR) ports is not acceptable for disabling camera functionality, as these methods have not been tested for efficacy.

If a written policy does not prohibit these devices in classified areas, this is a finding.

NOTE: The site should consider requiring CMD cameras be disabled via a CMD security policy.
Fix Text (F-40518r1_fix)
Update the site physical security policy to state that digital cameras (still and video) are not permitted in any SCIF or other areas where classified documents or information is stored, transmitted, or processed.