U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

NIST IR 8144 (Initial Public Draft)

Assessing Threats to Mobile Devices & Infrastructure: the Mobile Threat Catalogue

Date Published: September 2016
Comments Due: October 12, 2016 (public comment period is CLOSED)
Email Questions to: nistir8144@nist.gov

Author(s)

Joshua Franklin (NIST), Christopher Brown (MITRE), Spike Dog (MITRE), Neil McNab (MITRE), Sharon Voss-Northrop (MITRE), Michael Peck (MITRE), Bart Stidham (STS Mobile)

Announcement

The Mobile Threat Catalogue outlines a catalogue of threats to mobile devices and associated mobile infrastructure to support development and implementation of mobile security capabilities, best practices, and security solutions to better protect enterprise information technology (IT). Threats are divided into broad categories, primarily focused upon mobile applications and software, the network stack and associated infrastructure, mobile device and software supply chain, and the greater mobile ecosystem. Each threat identified is catalogued alongside explanatory and vulnerability information where possible, and alongside applicable mitigation strategies.

Draft NISTIR 8144 provides background information on mobile information systems and their attack surface is provided to assist readers in understanding threats contained within the Mobile Threat Catalogue (see link below). The NISTIR also outlines the structure of the Mobile Threat Catalogue.

Mobile security engineers and architects can leverage these documents to inform risk assessments, build threat models, enumerate the attack surface of their mobile infrastructure, and identify mitigations for their mobile deployments.

Abstract

Keywords

mobile; mobile device; mobile security; mobile device management; mobility management; telecommunications  ; ; enterprise mobility; cellular security
Control Families

System and Communications Protection

Documentation

Publication:
Draft NISTIR 8144 (pdf)

Supplemental Material:
Mobile Threat Catalogue (GitHub)
Press Release

Related NIST Publications:
SP 1800-12 (Draft)
SP 1800-12 (Draft)

Document History:
09/12/16: IR 8144 (Draft)

Topics

Security and Privacy

risk assessment, threats, vulnerability management

Technologies

mobile

Applications

communications & wireless