Google Android 13 MDFPP 3.3 BYOAD Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates No substantive changes
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
No substantive changes detected against the previous release. 14 rules matched cleanly.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GOOG-13-800200
- Vuln IDs
-
- V-258461
- Rule IDs
-
- SV-258461r929199_rule
Checks: C-62201r929197_chk
Verify the EMM system supporting the Google Android 13 BYOAD has been configured to conduct autonomous monitoring, compliance, and validation to ensure security/configuration settings of mobile devices do not deviate from the approved configuration baseline. The exact procedure will depend on the EMM system used at the site. If the EMM system supporting the Google Android 13 BYOAD has not been configured to conduct autonomous monitoring, compliance, and validation to ensure security/configuration settings of mobile devices, this is a finding.
Fix: F-62110r929198_fix
Configure the EMM system supporting the Google Android 13 BYOAD to conduct autonomous monitoring, compliance, and validation to ensure security/configuration settings of mobile devices do not deviate from the approved configuration baseline. The exact procedure will depend on the EMM system used at the site.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GOOG-13-800300
- Vuln IDs
-
- V-258462
- Rule IDs
-
- SV-258462r929202_rule
Checks: C-62202r929200_chk
Verify the EMM system supporting the Google Android 13 BYOAD has been configured to initiate autonomous monitoring, compliance, and validation prior to granting the BYOAD access to DOD information and IT resources. The exact procedure will depend on the EMM system used at the site. If the EMM system supporting the Google Android 13 BYOAD has not been configured to initiate autonomous monitoring, compliance, and validation prior to granting the BYOAD access to DOD information and IT resources, this is a finding.
Fix: F-62111r929201_fix
Configure the EMM system supporting the Google Android 13 BYOAD to initiate autonomous monitoring, compliance, and validation prior to granting the BYOAD access to DOD information and IT resources. The exact procedure will depend on the EMM system used at the site.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GOOG-13-800400
- Vuln IDs
-
- V-258463
- Rule IDs
-
- SV-258463r929205_rule
Checks: C-62203r929203_chk
Verify the EMM system supporting the Google Android 13 BYOAD has been configured to detect if the BYOAD native security controls are disabled. The exact procedure will depend on the EMM system used at the site. If the EMM system supporting the Google Android 13 BYOAD is not configured to detect if the BYOAD native security controls are disabled, this is a finding.
Fix: F-62112r929204_fix
Configure the EMM system supporting the Google Android 13 BYOAD to detect if the BYOAD native security controls are disabled. The exact procedure will depend on the EMM system used at the site.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GOOG-13-800500
- Vuln IDs
-
- V-258464
- Rule IDs
-
- SV-258464r929208_rule
Checks: C-62204r929206_chk
Verify an app vetting process is being used to vet apps before work profile apps are placed in the MDM app repository. If an app vetting process is not being used to vet apps before work profile apps are placed in the MDM app repository, this is a finding.
Fix: F-62113r929207_fix
Implement an app vetting process before work profile apps are placed in the MDM app repository.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GOOG-13-800700
- Vuln IDs
-
- V-258465
- Rule IDs
-
- SV-258465r929211_rule
Checks: C-62205r929209_chk
Verify the EMM detection/monitoring system is configured to use continuous monitoring of enrolled Google Android 13 BYOAD. The exact procedure will depend on the EMM system used at the site. If the EMM detection/monitoring system is not configured to use continuous monitoring of enrolled Google Android 13 BYOAD, this is a finding.
Fix: F-62114r929210_fix
Configure the EMM detection/monitoring system to use continuous monitoring of enrolled Google Android 13 BYOAD. The exact procedure will depend on the EMM system used at the site.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GOOG-13-800800
- Vuln IDs
-
- V-258466
- Rule IDs
-
- SV-258466r929214_rule
Checks: C-62206r929212_chk
Verify the EMM has been configured to either disable access to DOD data, IT systems, and user accounts on the Google Android 13 BYOAD or wipe the work profile if it has been detected that native BYOAD security controls are disabled (e.g., jailbroken/rooted). The exact procedure will depend on the EMM system used at the site. If the EMM has not been configured to either disable access to DOD data, IT systems, and user accounts on the Google Android 13 BYOAD or wipe the work profile if it has been detected that native BYOAD security controls are disabled, this is a finding.
Fix: F-62115r929213_fix
Configure the EMM to either disable access to DOD data and IT systems and user accounts on the Google Android 13 BYOAD or wipe the work profile if it has been detected that native BYOAD security controls are disabled (e.g., jailbroken/rooted). The exact procedure will depend on the EMM system used at the site.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GOOG-13-800900
- Vuln IDs
-
- V-258467
- Rule IDs
-
- SV-258467r929217_rule
Checks: C-62207r929215_chk
Verify the EMM system has been configured to either disable access to DOD data and IT systems and user accounts or the work profile if it has detected the Google Android 13 BYOAD device has known malicious, blocked, or prohibited managed applications, or configured to access nonapproved third-party applications stores for managed apps. The exact procedure will depend on the EMM system used at the site. If the EMM system has not been configured to either disable access to DOD data and IT systems and user accounts or wipe the work profile if it has detected the Google Android 13 BYOAD device has known malicious, blocked, or prohibited managed applications, or configured to access nonapproved third-party applications stores for managed apps, this is a finding.
Fix: F-62116r929216_fix
Configure the EMM system to either disable access to DOD data and IT systems and user accounts or wipe the work profile if it has detected the Google Android 13 BYOAD device has known malicious, blocked, or prohibited managed applications, or configured to access nonapproved third-party applications stores for managed apps. The exact procedure will depend on the EMM system used at the site.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GOOG-13-801000
- Vuln IDs
-
- V-258468
- Rule IDs
-
- SV-258468r929220_rule
Checks: C-62208r929218_chk
Verify the EMM system is configured to wipe the work profile if the Google Android 13 BYOAD is no longer receiving security or software updates. The exact procedure will depend on the EMM system used at the site. If the EMM system is not configured to wipe the work profile if the Google Android 13 BYOAD is no longer receiving security or software updates, this is a finding.
Fix: F-62117r929219_fix
Configure the EMM system so the work profile is removed if the Google Android 13 BYOAD is no longer receiving security or software updates. The exact procedure will depend on the EMM system used at the site.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- GOOG-13-801100
- Vuln IDs
-
- V-258469
- Rule IDs
-
- SV-258469r929223_rule
Checks: C-62209r929221_chk
Verify the EMM system and DOD enterprise have been configured to limit the Google Android 13 BYOAD access to only AO-approved enterprise IT resources. The exact procedure will depend on the EMM system used and IT resources at the site. If the EMM system and DOD enterprise have not been configured to limit Google Android 13 BYOAD access to only AO-approved enterprise IT resources, this is a finding.
Fix: F-62118r929222_fix
Configure the EMM system and DOD enterprise to limit the Google Android 13 BYOAD access to only AO-approved enterprise IT resources. The exact procedure will depend on the EMM system used and IT resources at the site.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- GOOG-13-802000
- Vuln IDs
-
- V-258470
- Rule IDs
-
- SV-258470r929226_rule
Checks: C-62210r929224_chk
Verify the EMM system supporting the Google Android 13 BYOAD is NIAP-validated (included on the NIAP list of compliant products or products in evaluation). If not, verify the DOD CIO has granted an Approved Exception to Policy (E2P). Note: For a VMI solution, both the client and server components must be NIAP compliant. If the EMM system supporting the Google Android 13 BYOAD is not NIAP-validated (included on the NIAP list of compliant products or products in evaluation) and the DOD CIO has not granted an Approved Exception to Policy (E2P), this is a finding.
Fix: F-62119r929225_fix
Only use an EMM system supporting the Google Android 13 BYOAD that is NIAP validated (included on the NIAP list of compliant products or products in evaluation), unless the DOD CIO has granted an Approved Exception to Policy (E2P). Note: For a VMI solution, both the client and server components must be NIAP compliant.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- GOOG-13-802100
- Vuln IDs
-
- V-258471
- Rule IDs
-
- SV-258471r929229_rule
Checks: C-62211r929227_chk
Verify the user agreement includes a description of what personal data and information is being monitored, collected, or managed by the EMM system or deployed agents or tools. If the user agreement does not include a description of what personal data and information is being monitored, collected, or managed by the EMM system or deployed agents or tools, this is a finding.
Fix: F-62120r929228_fix
Include a description of what personal data and information is being monitored, collected, or managed by the EMM system or deployed agents or tools in the user agreement.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- GOOG-13-802200
- Vuln IDs
-
- V-258472
- Rule IDs
-
- SV-258472r929232_rule
Checks: C-62212r929230_chk
Verify the DOD Mobile Service Provider or ISSO/ISSM do not allow BYOADs in facilities where personally owned mobile devices are prohibited. If the DOD Mobile Service Provider or ISSO/ISSM allows BYOADs in facilities where personally owned mobile devices are prohibited, this is a finding.
Fix: F-62121r929231_fix
Do not allow BYOADs in facilities where personally owned mobile devices are prohibited.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- GOOG-13-802300
- Vuln IDs
-
- V-258473
- Rule IDs
-
- SV-258473r929235_rule
Checks: C-62213r929233_chk
Verify Google Android 13 BYOADs are prohibited in DOD facilities that prohibit mobile devices with cameras and microphones. If for DOD sites that prohibit mobile devices with cameras and microphones, Google Android 13 BYOADs have not been prohibited from the facility by the ISSO/ISSM, this is a finding.
Fix: F-62122r929234_fix
Do not allow Google Android 13 BYOADs in DOD facilities where mobile phone cameras and/or microphones are prohibited.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- GOOG-13-802800
- Vuln IDs
-
- V-258474
- Rule IDs
-
- SV-258474r929238_rule
Checks: C-62214r929236_chk
Verify the mobile device used for BYOAD is NIAP validated (included on the NIAP list of compliant products or products in evaluation). If the mobile device used for BYOAD is not NIAP validated (included on the NIAP list of compliant products or products in evaluation), this is a finding.
Fix: F-62123r929237_fix
Use only mobile devices for BYOAD that are NIAP validated (included on the NIAP list of compliant products or products in evaluation).