Code Risk Categories: Dod Mobile

: Use of this category is strictly controlled and often prohibited unless the code is signed by a trusted US certificate signing authority. Category 2: Limited Access (Medium Risk)

: Historically, this included ActiveX and Shockwave Flash , which could operate outside a restricted "sandbox" environment to interact directly with the operating system. Dod Mobile Code Risk Categories

: Systems often run code (like JavaScript on a website) without real-time human review. : Use of this category is strictly controlled

: While these may have known vulnerabilities, they support fine-grained security safeguards and pose a limited overall risk to IT systems. : While these may have known vulnerabilities, they

: Code that has broad, unmediated access to workstation, server, and remote system services and resources.

While the primary policy governing these categories is , the specific risk tiers are structured by the level of access the code has to system resources. The Three Mobile Code Risk Categories

: Flaws in the containment models of Category 2 code can allow it to reach sensitive data it should not see.