36 MAC Pt. 1, R. 4.4
Portable and Mobile Device Access
Cite as 36 Miss. Admin. Code Pt. 1, R. 4.4
Portable and Mobile Device Access
A. Each agency must ensure that all portable and mobile devices are controlled and
configured securely. Portable and mobile devices are computing devices that have a
small form factor such that it can easily be carried by a single individual; is designed
to operate without a physical connection; possesses local, non-removable or
removable data storage; and includes a self-contained power source. Portable and
mobile device functionality may also include voice communication capabilities, on-
board sensors that allow the device to capture information, and/or built-in features for
synchronizing local data with remote locations. Examples include smart phones,
laptops, and tablets. These devices are typically associated with a single individual.
1. Where possible, require multi-factor access for portable and mobile devices.
B. Each agency must ensure that all confidential information stored or processed on
portable and mobile devices is encrypted (whole-disk encryption, full-device
encryption, container-based encryption, etc.).
1. Utilize technology that can remotely wipe portable and mobile devices when
deemed appropriate such as lost or stolen devices, or when an individual no
longer supports the enterprise.
2. ITS recommends using a management platform that allows central
administration of the appropriate security policy to all devices supported by
the agency.
C. Each agency must enforce automatic device lockout following a predetermined
threshold of local failed authentication attempts on all portable and mobile devices.
1. For laptops, do not allow more than 20 failed authentication attempts: for
tablets and smartphones, no more than 10 failed authentication attempts.
D. Each agency must ensure that any device connected to the Enterprise State Network
has only one active connected network interface at any time. For example, if plugged
into Ethernet, Wi-Fi is disabled.