The BlackBerry Enterprise Mobility Server (BEMS) must be configured to use HTTPS.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-254716BEMS-03-013500SV-254716r879887_ruleCCI-000068high
Description
Preventing the disclosure of transmitted information requires that applications take measures to employ some form of cryptographic mechanism to protect the information during transmission to web applications. This is usually achieved through the use of HTTPS.
STIGDate
BlackBerry Enterprise Mobility Server 3.x Security Technical Implementation Guide2023-05-17

Related Frameworks

3 paths across 3 frameworks
NIST 800-531 mapping
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
3.1.13
1.00
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000068
1.00
  • DISA · V1R2 · disa_xccdf · related

Details

Check Text (C-254716r879887_chk)

Verify BEMS has been configured to use HTTPS as follows: 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "BlackBerry Dynamics". 3. In the Protocol drop-down list, verify "HTTPS" is selected. If HTTPS is not configured on BEMS, this is a finding.

Fix Text (F-58273r861872_fix)

Configure BEMS to use HTTPS as follows: 1. In the BEMS Dashboard, under "BEMS System Settings", click "BEMS Configuration". 2. Click "BlackBerry Dynamics". 3. In the Protocol drop-down list, select "HTTPS".