STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to STIGs

BlackBerry Enterprise Mobility Server 3.x Security Technical Implementation Guide

Version

V1R2

Release Date

May 17, 2023

SCAP Benchmark ID

BEMS_3-x_STIG

Total Checks

27

Tags

other
CAT I: 2CAT II: 24CAT III: 1

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (27)

V-254706MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must protect log information from any type of unauthorized read access.V-254707MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must protect log information from unauthorized modification.V-254708MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must protect log information from unauthorized deletion.V-254709MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) platform must be protected by a DOD-approved firewall.V-254710MEDIUMThe firewall protecting the BEMS must be configured to restrict all network traffic to and from all addresses with the exception of ports, protocols, and IP address ranges required to support BEMS functions.V-254711MEDIUMThe firewall protecting the BlackBerry Enterprise Mobility Server (BEMS) must be configured so that only DOD-approved ports, protocols, and services are enabled.V-254712MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must protect the confidentiality and integrity of transmitted information through the use of an approved TLS version.V-254713MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must remove all export ciphers to protect the confidentiality and integrity of transmitted information.V-254714MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must be configured to have at least one user in the following Administrator roles: Server primary administrator, auditor.V-254715MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must be configured to use Windows Authentication for the database connection.V-254716HIGHThe BlackBerry Enterprise Mobility Server (BEMS) must be configured to use HTTPS.V-254717MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must be configured to use DOD certificates for SSL.V-254718MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) must be configured with an inactivity timeout of 15 minutes or less.V-254719MEDIUMIf the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.V-254720MEDIUMIf the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Integrated Authentication for the Exchange connection.V-254721MEDIUMIf the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to Enable SSL LDAP when using LDAP Lookup for users.V-254722MEDIUMIf the Mail service (Push Notifications support for BlackBerry Work) is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to Enable SSL LDAP for certificate directory lookup.V-254723MEDIUMIf the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.V-254724MEDIUMIf the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable SSL support for BlackBerry Proxy and use only DOD approved certificates.V-254725MEDIUMIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use Windows Authentication for the database connection.V-254726MEDIUMIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use NTLM authentication.V-254727HIGHIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to use SSL for LDAP lookup to connect to the Office Web App Server (e.g., SharePoint).V-254728MEDIUMIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable audit logs.V-254729MEDIUMThe BlackBerry Enterprise Mobility Server (BEMS) server must be configured to enable FIPS mode.V-254730MEDIUMIf the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable the Web Proxy.V-254731LOWIf the BlackBerry Presence service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured with the whitelisting control to limit presence subscriptions to only single domain/tenant.V-254732MEDIUMIf the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable the proxy server authentication type (if a proxy is used).