Free DISA STIG and SRG Library | Vaulted

V-24953

Site physical security policy must include a statement outlining whether CMDs with digital cameras (still and video) are permitted or prohibited on or in this DoD facility.

Finding ID
WIR-SPP-001
Rule ID
SV-30690r4_rule
Severity
Cat III
CCE
(None)
Group Title
Site CMD camera policy
CCI
(None)
Target Key
(None)
Documentable
No
Discussion

Mobile devices with cameras are easily used to photograph sensitive information and areas if not addressed. Sites must establish, document, and train on how to mitigate this threat.

Fix Text

Update the security documentation to include a statement outlining whether CMDs with digital cameras (still and video) are allowed in the facility.

Check Content

This requirement applies to mobile operating system (OS) CMDs. Work with traditional reviewer to review site’s physical security policy. Verify the site addresses CMDs with embedded cameras. If there is no written physical security policy outlining whether CMDs with cameras are permitted or prohibited on or in this DoD facility, this is a finding.

Responsibility

Security Manager

IA Controls

ECWN-1