STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to STIGs

BlackBerry Enterprise Mobility Server 2.x Security Technical Implementation Guide

Version

V1R3

Release Date

May 15, 2020

SCAP Benchmark ID

BEMS_2-x_STIG

Total Checks

23

Tags

other
CAT I: 2CAT II: 21CAT III: 0

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (23)

V-79003MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must protect log information from any type of unauthorized read access.V-79005MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must protect log information from unauthorized modification.V-79007MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must protect log information from unauthorized deletion.V-79009MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) platform must be protected by a DoD-approved firewall.V-79011MEDIUMThe firewall protecting the BlackBerry Enterprise Mobility Server (BEMS) must be configured to restrict all network traffic to and from all addresses with the exception of ports, protocols, and IP address ranges required to support BEMS functions.V-79013MEDIUMThe firewall protecting the BlackBerry Enterprise Mobility Server (BEMS) must be configured so that only DoD-approved ports, protocols, and services are enabled. See the DoD Ports, Protocols, Services Management (PPSM) Category Assurance Levels (CAL) list for DoD-approved ports, protocols, and services.V-79015MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must protect the confidentiality and integrity of transmitted information through the use of an approved TLS version.V-79017MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must remove all export ciphers to protect the confidentiality and integrity of transmitted information.V-79019MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must be configured to have at least one user in the following Administrator roles: Server primary administrator, auditor.V-79021MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must be configured to use Windows Authentication for the database connection.V-79023HIGHThe BlackBerry Enterprise Mobility Server (BEMS) must be configured to use HTTPS.V-79025MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must be configured to use DoD certificates for SSL.V-79027MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must be configured with an inactivity timeout of 15 minutes or less.V-79029MEDIUMIf the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.V-79031MEDIUMIf the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Integrated Authentication for the Exchange connection.V-79033MEDIUMIf the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to Enable SSL LDAP when using LDAP Lookup for users.V-79035MEDIUMIf the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to Enable SSL LDAP for certificate directory lookup.V-79037MEDIUMIf the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.V-79039MEDIUMIf the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable SSL support for BlackBerry Proxy and use only DoD approved certificates.V-79041MEDIUMIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.V-79043MEDIUMIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use NTLM authentication.V-79045HIGHIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use SSL for LDAP lookup to connect to the Office Web App Server (e.g., SharePoint).V-79047MEDIUMIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable audit logs.