DoD Compliance · STIG

Samsung Android OS 17 with Knox 3.x COBO Security Technical Implementation Guide

V1R1 · · · Released 28 Jul 2026 · 45 rules
Compare

Pick two releases to diff their requirements.

View

Open a previous version of this STIG.

This Security Technical Implementation Guide is published as a tool to improve the security of Department of War (DoW) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.
Sort by
b
Samsung Android 17 must allow only the administrator (EMM) to install/remove DoW root and intermediate PKI certificates.
CM-6 - Medium - CCI-000366 - V-286294 - SV-286294r1256079_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-003800
Vuln IDs
  • V-286294
Rule IDs
  • SV-286294r1256079_rule
DoW root and intermediate PKI certificates are used to verify the authenticity of PKI certificates of users and web services. If the user is allowed to remove root and intermediate certificates, the user could allow an adversary to falsely sign a certificate in such a way that it could not be detected. Restricting the ability to remove DoW root and intermediate PKI certificates to the administrator mitigates this risk. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-90976r1256077_chk

COPE: Review the configuration to determine if the Samsung Android device's work profile is preventing the user from removing DoW root and intermediate PKI certificates. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the work profile restrictions, verify "Configure credentials" is set to "Disallow". On the Samsung Android device: 1. Open Settings >> Security and privacy >> More security settings >> View security certificates. 2. In the System tab, verify no listed certificate in the work profile can be untrusted. 3. In the User tab, verify no listed certificate in the work profile can be removed. If on the management tool the device "Configure credentials" is not set to "Disallow", or on the Samsung Android device a certificate can be untrusted or removed, this is a finding. COBO: Review the configuration to determine if the Samsung Android devices are preventing users from removing DoW root and intermediate PKI certificates. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device restrictions, verify "Configure credentials" is set to "Disallow". On the Samsung Android device: 1. Open Settings >> Security and privacy >> More security settings >> View security certificates. 2. In the System tab, verify no listed certificate in the device can be untrusted. 3. In the User tab, verify no listed certificate in the device can be removed. If on the management tool in the device restrictions "Configure credentials" is not set to "Disallow", or on the Samsung Android device a certificate can be untrusted or removed, this is a finding.

Fix: F-90881r1256078_fix

COPE: Configure the Samsung Android device's work profile to prevent users from removing DoW root and intermediate PKI certificates. On the management tool, in the work profile restrictions, set "Configure credentials" to "Disallow". COBO: Configure the Samsung Android device to prevent the user from removing DoW root and intermediate PKI certificates. On the management tool, in the device restrictions, set "Configure credentials" to "Disallow".

a
Samsung Android 17 must [DoW-restricted selection: allow the user to choose whether to accept the certificate in these cases, not accept the certificate] when it cannot establish a connection to determine the validity of a certificate.
IA-5 - Low - CCI-000185 - V-286298 - SV-286298r1256081_rule
RMF Control
IA-5
Severity
L
CCI
CCI-000185
Version
KNOX-17-004200
Vuln IDs
  • V-286298
Rule IDs
  • SV-286298r1256081_rule
Certificate-based security controls depend on the ability of the system to verify the validity of a certificate. If the MOS were to accept an invalid certificate, it could take unauthorized actions, resulting in unanticipated outcomes. At the same time, if the MOS were to disable functionality when it could not determine the validity of the certificate, this could result in a denial of service. Therefore, the ability to provide exceptions is appropriate to balance the tradeoff between security and functionality. Always accepting certificates when they cannot be determined to be valid is the most extreme exception policy and is not appropriate in the DoW context. Involving an administrator or user in the exception decision mitigates this risk to some degree. SFR ID: FIA_X509_EXT.2.2/FP for X.509
Checks: C-90980r1256080_chk

Verify requirement KNOX-17-009200 (Common Criteria mode) has been implemented. If "Common Criteria mode" has not been implemented, this is a finding.

Fix: F-90885r1255543_fix

Implement "Common Criteria mode" (refer to requirement KNOX-17-009200).

b
Samsung Android 17 must be configured to enforce a minimum password length of six characters.
Medium - CCI-004066 - V-286308 - SV-286308r1256087_rule
RMF Control
Severity
M
CCI
CCI-004066
Version
KNOX-17-005200
Vuln IDs
  • V-286308
Rule IDs
  • SV-286308r1256087_rule
Password strength is a measure of the effectiveness of a password in resisting guessing and brute force attacks. The ability to crack a password is a function of how many attempts an adversary is permitted, how quickly an adversary can do each attempt, and the size of the password space. The longer the minimum length of the password is, the larger the password space. Having a too-short minimum password length significantly reduces password strength, increasing the chance of password compromise and resulting in device and data compromise. SFR ID: FMT_SMF_EXT.1.1 #1
Checks: C-90990r1256085_chk

Review the configuration to determine if the Samsung Android device is enforcing a minimum password length of six characters. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device password policies, verify "minimum password length" is set to "6". On the Samsung Android device: 1. Open Settings >> Lock screen and AOD >> Screen lock and biometrics. 2. Enter current password. 3. Tap "PIN". 4. Verify the text "PIN must contain at least", followed by a value of at least "6 digits", appears above the PIN entry. If on the management tool "minimum password length" is not set to "6", or on the Samsung Android device the text "PIN must contain at least" is followed by a value of less than "6 digits", this is a finding.

Fix: F-90895r1256086_fix

Configure the Samsung Android device to enforce a minimum password length of six characters. On the management tool, in the device password policies, set "minimum password length" to "6".

b
Samsung Android 17 must be configured to not allow passwords that include more than four repeating or sequential characters.
Medium - CCI-004066 - V-286309 - SV-286309r1256090_rule
RMF Control
Severity
M
CCI
CCI-004066
Version
KNOX-17-005300
Vuln IDs
  • V-286309
Rule IDs
  • SV-286309r1256090_rule
Password strength is a measure of the effectiveness of a password in resisting guessing and brute force attacks. Passwords that contain repeating or sequential characters are significantly easier to guess than those that do not contain repeating or sequential characters. Therefore, disallowing repeating or sequential characters increases password strength and decreases risk. SFR ID: FMT_SMF_EXT.1.1 #1
Checks: C-90991r1256088_chk

Review the configuration to determine if the Samsung Android devices are disallowing passwords containing more than four repeating or sequential characters. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device password policies, verify "minimum password quality" is set to "Numeric(Complex)" or better. On the Samsung Android device: 1. Open Settings >> Lock screen and AOD >> Screen lock and biometrics. 2. Enter current password. 3. Tap "PIN". 4. Verify PINs with more than four repeating or sequential numbers are not accepted. If on the management tool "minimum password quality" is not set to "Numeric(Complex)" or better, or on the Samsung Android device a password with more than four repeating or sequential numbers is accepted, this is a finding.

Fix: F-90896r1256089_fix

Configure the Samsung Android devices to disallow passwords containing more than four repeating or sequential characters. On the management tool, in the device password policies, set "minimum password quality" to "Numeric(Complex)" or better. If the management tool does not support "Numeric(Complex)" but does support "Numeric", Knox Platform for Enterprise (KPE) can be used to achieve STIG compliance. In this case, configure this policy with value "Numeric" and use an additional KPE policy (innately by the management tool or via KSP) "Maximum Numeric Sequence Length" with value "4".

b
Samsung Android 17 must be configured to lock the display after 15 minutes (or less) of inactivity.
AC-11 - Medium - CCI-000057 - V-286310 - SV-286310r1256093_rule
RMF Control
AC-11
Severity
M
CCI
CCI-000057
Version
KNOX-17-005400
Vuln IDs
  • V-286310
Rule IDs
  • SV-286310r1256093_rule
The screen lock timeout must be set to a value that helps protect the device from unauthorized access. Having a too-long timeout would increase the window of opportunity for adversaries who gain physical access to the mobile device through loss, theft, etc. Such devices are much more likely to be in an unlocked state when acquired by an adversary, thus granting immediate access to the data on the mobile device. The maximum timeout period of 15 minutes has been selected to balance functionality and security; shorter timeout periods may be appropriate depending on the risks posed to the mobile device. SFR ID: FMT_SMF_EXT.1.1 #2
Checks: C-90992r1256091_chk

Review the configuration to determine if the Samsung Android devices are locking the device display after 15 minutes (or less) of inactivity. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device password policies, verify "max time to screen lock" is set to "15 minutes" or less. On the Samsung Android device: 1. Open Settings >> Lock screen and AOD. 2. Verify "Secure lock settings" is present and tap it. 3. Enter current password. 4. Tap "Auto lock when screen turns off". 5. Verify the listed timeout values are 15 minutes or less. If on the management tool "max time to screen lock" is not set to "15 minutes" or less, or on the Samsung Android device "Secure lock settings" is not present and the listed screen timeout values include durations of more than 15 minutes, this is a finding.

Fix: F-90897r1256092_fix

Configure the Samsung Android devices to lock the device display after 15 minutes (or less) of inactivity. On the management tool, in the device password policies, set "max time to screen lock" to "15 minutes" or less. A device password must be set for "max time to screen lock" to become active.

b
Samsung Android 17 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity - Disable trust agents.
IA-2 - Medium - CCI-000765 - V-286311 - SV-286311r1256096_rule
RMF Control
IA-2
Severity
M
CCI
CCI-000765
Version
KNOX-17-005500
Vuln IDs
  • V-286311
Rule IDs
  • SV-286311r1256096_rule
The screen lock timeout must be set to a value that helps protect the device from unauthorized access. Having a too-long timeout would increase the window of opportunity for adversaries who gain physical access to the mobile device through loss, theft, etc. Such devices are much more likely to be in an unlocked state when acquired by an adversary, thus granting immediate access to the data on the mobile device. The maximum timeout period of 15 minutes has been selected to balance functionality and security; shorter timeout periods may be appropriate depending on the risks posed to the mobile device. SFR ID: FMT_SMF_EXT.1.1 #2
Checks: C-90993r1256094_chk

Review the configuration to determine if the Samsung Android devices are disabling Trust Agents. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device restrictions, verify "Trust Agents" are set to "Disable". On the Samsung Android device: 1. Open Settings >> Security and privacy >> More security settings >> Trust Agents. 2. Verify all listed trust agents are disabled and cannot be enabled. If a trust agent is not disabled in the list, verify for that trust agent, all of its listed trustlets are disabled and cannot be enabled. If on the management tool "Trust Agents" are not set to "Disable", or on the Samsung Android device a "Trust Agent" or "Trustlet" can be enabled, this is a finding. Note: If the management tool has been correctly configured but a trust agent is still enabled, configure the "List of approved apps listed in managed Google Play" to disable it; refer to KNOX-17-005800. Exception: Trust agents may be used if the authorizing official (AO) allows a screen lock timeout after four hours (or more) of inactivity. This may be applicable to tactical use cases.

Fix: F-90898r1256095_fix

Configure the Samsung Android devices to disable trust agents. On the management tool, in the device restrictions, set "Trust Agents" to "Disable".

b
Samsung Android 17 must be configured to not allow more than 10 consecutive failed authentication attempts.
AC-7 - Medium - CCI-000044 - V-286312 - SV-286312r1256099_rule
RMF Control
AC-7
Severity
M
CCI
CCI-000044
Version
KNOX-17-005600
Vuln IDs
  • V-286312
Rule IDs
  • SV-286312r1256099_rule
The more attempts an adversary has to guess a password, the more likely the adversary will enter the correct password and gain access to resources on the device. Setting a limit on the number of attempts mitigates this risk. Setting the limit at 10 or less gives authorized users the ability to make a few mistakes when entering the password but still provides adequate protection against dictionary or brute force attacks on the password. SFR ID: FMT_SMF_EXT.1.1 #2
Checks: C-90994r1256097_chk

Review the configuration to determine if the Samsung Android devices are allowing only 10 or fewer consecutive failed authentication attempts. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device password policies, verify "max password failures for local wipe" is set to "10" attempts or less. On the Samsung Android device: 1. Open Settings >> Lock screen and AOD. 2. Verify "Secure lock settings" is present and tap it. 3. Enter current password. 4. Verify "Auto factory reset" is grayed out, and cannot be configured. Note: When "Auto factory reset" is grayed out, this indicates the Administrator (MDM) is in control of the setting to wipe the device after 10 or fewer consecutive failed authentication attempts. If on the management tool "max password failures for local wipe" is not set to "10" attempts or less, or on the Samsung Android device the "Auto factory reset" menu can be configured, this is a finding.

Fix: F-90899r1256098_fix

Configure the Samsung Android devices to allow only 10 or fewer consecutive failed authentication attempts. On the management tool, in the device password policies, set "max password failures for local wipe" to "10" attempts or fewer. A device password must be set for "max password failures for local wipe" to become active.

b
Samsung Android 17 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DoW-approved commercial app repository, MDM server, mobile application store].
CM-6 - Medium - CCI-000366 - V-286313 - SV-286313r1256102_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-005700
Vuln IDs
  • V-286313
Rule IDs
  • SV-286313r1256102_rule
Forcing all applications to be installed from authorized application repositories can prevent unauthorized and malicious applications from being installed and executed on mobile devices. Allowing such installations and executions could cause a compromise of DoW data accessible by these unauthorized/malicious applications. SFR ID: FMT_SMF_EXT.1.1 #8
Checks: C-90995r1256100_chk

Review the configuration to determine if the Samsung Android devices are disabling unauthorized application repositories. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the work profile restrictions, verify "installs from unknown sources globally" is set to "Disallow". On the Samsung Android device: 1. Open Settings >> Security and privacy >> More security settings >> Install unknown apps. 2. Verify that each app listed has the status "Disabled" under the app name or no apps are listed. On COPE devices, confirm this in both the "Personal" and "Work" tabs. If on the management tool "installs from unknown sources globally" is not set to "Disallow", or on the Samsung Android device an app is listed with a status other than "Disabled", this is a finding.

Fix: F-90900r1256101_fix

Configure the Samsung Android devices to disable unauthorized application repositories. COPE: On the management tool, in the work profile restrictions, set "installs from unknown sources globally" to "Disallow". COBO: On the management tool, in the device restrictions, set "installs from unknown sources globally" to "Disallow". Note: Google Play must not be disabled. Disabling Google Play will cause system instability and critical updates will not be received.

b
Samsung Android 17 must be configured to enforce an application installation policy by specifying an application allow list that restricts applications by the following characteristic: names.
CM-7 - Medium - CCI-001764 - V-286314 - SV-286314r1256231_rule
RMF Control
CM-7
Severity
M
CCI
CCI-001764
Version
KNOX-17-005800
Vuln IDs
  • V-286314
Rule IDs
  • SV-286314r1256231_rule
The application allow list, in addition to controlling the installation of applications on the MD, must control user access/execution of all core and preinstalled applications, or the MD must provide an alternate method of restricting user access/execution to core and preinstalled applications. Core application: Any application integrated into the OS by the OS or MD vendor. Preinstalled application: Additional noncore applications included in the OS build by the OS vendor, MD vendor, or wireless carrier. Requiring all authorized applications to be in an application allow list prevents the execution of any applications (e.g., unauthorized, malicious) that are not part of the allow list. Failure to configure an application allow list properly could allow unauthorized and malicious applications to be downloaded, installed, and executed on the mobile device, causing a compromise of DoW data accessible by these applications. The application allow list, in addition to controlling the installation of applications on the MD, must control user access/execution of all core applications (included in the OS by the OS vendor) and preinstalled applications (provided by the MD vendor and wireless carrier), or the MD must provide an alternate method of restricting user access/execution to core and preinstalled applications. SFR ID: FMT_SMF_EXT.1.1 #8
Checks: C-90996r1256103_chk

COPE: Review the configuration to determine if the work profile on the Samsung Android device is allowing users to install only applications that have been approved by the authorizing official (AO). COBO: Review the configuration to determine if the Samsung Android devices are allowing users to install only applications that have been approved by the AO. This validation procedure is performed only on the management tool. On the management tool, in the app catalog for managed Google Play, verify that only AO-approved apps are available. If on the management tool the app catalog for managed Google Play includes non-AO-approved apps, this is a finding.

Fix: F-90901r1256230_fix

COPE: Configure the work profile on Samsung Android devices to allow users to install only applications that have been approved by the AO. COBO: Configure Samsung Android devices to allow users to install only applications that have been approved by the AO. In addition to any local policy, the AO must not approve applications that have certain prohibited characteristics, which are covered in KNOX-17-005900. On the management tool, in the app catalog for managed Google Play, add each AO-approved app to be available. Note: Managed Google Play is an allowed app store.

b
The Samsung Android 17 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DoW cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DoW servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with the user; - Payment processing; - Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers; - Backs up its own data to a remote system; and - Renders TV shows and movies.
IA-7 - Medium - CCI-000803 - V-286315 - SV-286315r1256108_rule
RMF Control
IA-7
Severity
M
CCI
CCI-000803
Version
KNOX-17-005900
Vuln IDs
  • V-286315
Rule IDs
  • SV-286315r1256108_rule
Requiring all authorized applications to be in an application allow list prevents the execution of any applications (e.g., unauthorized, malicious) that are not part of the allow list. Failure to configure an application allow list properly could allow unauthorized and malicious applications to be downloaded, installed, and executed on the mobile device, causing a compromise of DoW data accessible by these applications. Applications with the listed characteristics have features that can cause the compromise of sensitive DoW data or have features with no known application in the DoW environment. Application note: The application allow list, in addition to controlling the installation of applications on the MD, must control user access/execution of all core and preinstalled applications, or the MD must provide an alternate method of restricting user access/execution to core and preinstalled applications. Core application: Any application integrated into the OS by the OS or MD vendor. Preinstalled application: Additional noncore applications included in the OS build by the OS vendor, MD vendor, or wireless carrier. SFR ID: FMT_SMF_EXT.1.1 #8
Checks: C-90997r1256106_chk

Verify requirement KNOX-17-005800 (managed Google Play) has been implemented. Verify no apps with unapproved apps are listed in approved apps. If managed Google Play has not been implemented or unapproved apps are allowed, this is a finding.

Fix: F-90902r1256107_fix

The authorizing official (AO) must not approve applications with the following characteristics for installation by users in the work profile: - Back up MD data to non-DoW cloud servers (including user and application access to cloud backup services); - Transmit MD diagnostic data to non-DoW servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with the user; - Payment processing; - Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs, display screens (screen mirroring), or printers; - Apps that backup their own data to a remote system; and - Apps that render TV shows and movies. Implement managed Google Play (refer to requirement KNOX-17-005800).

b
The Samsung Android 17 allow list must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini.
IA-7 - Medium - CCI-000803 - V-286316 - SV-286316r1256111_rule
RMF Control
IA-7
Severity
M
CCI
CCI-000803
Version
KNOX-17-006000
Vuln IDs
  • V-286316
Rule IDs
  • SV-286316r1256111_rule
Sensitive DoW data could be exposed when an AI app processes device data in the cloud. SFR ID: FMT_SMF_EXT.1.1 #8
Checks: C-90998r1256109_chk

Review managed Samsung Android 17 device configuration settings to determine if the mobile device has an AI application that processes device data in the cloud, including Google Gemini. Verify requirement KNOX-17-009100 (disallow modify accounts) has been implemented. Verify that the Knox Platform for Enterprise (KPE) API "isIntelligenceOnlineProcessingAllowed()" returns false or that the KSP configuration has the restriction "Allow process data only on device" set to true. If any AI application that processes data in the cloud are included in the MDM console of allowed apps or "Allow process data only on device" is not set to true, this is a finding.

Fix: F-90903r1256110_fix

This validation procedure is performed only on the EMM administration console. On the EMM console: 1. Review the list of selected Managed Google Play apps. 2. Verify no AI applications that process device data in the cloud, including Google Gemini, are included. Note: This restriction does not include Galaxy on-device AI. Galaxy on-device AI is a ""built-in" capability of Android 17 and processes device data on the device." If the EMM console device policy includes AI applications that process device data in the cloud, including Google Gemini, this is a finding. Disallow modify accounts (refer to requirement KNOX-17-009100). If "disallow modify accounts" has not been implemented, this is a finding. Apply the "Disallow Intelligence Online Processing" using the KPE API or KSP. The KPE API is allowIntelligenceOnlineProcessing(false) and the KSP restriction is "Allow process data only on device", which should be set to true.

b
Samsung Android 17 must be configured to not display the following (work profile) notifications when the device is locked: All notifications.
AC-11 - Medium - CCI-000060 - V-286317 - SV-286317r1256772_rule
RMF Control
AC-11
Severity
M
CCI
CCI-000060
Version
KNOX-17-006100
Vuln IDs
  • V-286317
Rule IDs
  • SV-286317r1256772_rule
Many mobile devices display notifications on the lock screen so that users can obtain relevant information in a timely manner without having to frequently unlock the phone to determine if there are new notifications. However, in many cases, these notifications can contain sensitive information. When they are available on the lock screen, an adversary can see them merely by being in close physical proximity to the device. Configuring the MOS to not send notifications to the lock screen mitigates this risk. The requirement statement specifies the DoW-mandated configuration of this MDFPP element. The STIG author must select "all notifications" if there is no other means to administratively restrict applications from issuing notifications in the locked state where those notifications could include DoW sensitive information. SFR ID: FMT_SMF_EXT.1.1 #18
Checks: C-90999r1256112_chk

Review the configuration to determine if the Samsung Android devices are not displaying (work environment) notifications when the device is locked. Notifications of incoming phone calls are acceptable even when the device is locked. This validation procedure is performed on both the management tool administration console and the Samsung Android device. On the management tool, in the work profile restrictions section, verify "Unredacted Notifications" is set to "Disallow". COPE: On the Samsung Android device: 1. Open Settings >> Notifications >> Lock screen. 2. Verify configuration of "Sensitive work profile notifications" is disabled. If on the management tool "Unredacted Notifications" is not set to "Disallow", or on the Samsung Android device "Sensitive work profile notifications" is not disabled, this is a finding. COBO: On the Samsung Android device: 1. Open Settings >> Notifications. 2. Verify "Lock screen" menu is disabled. If on the management tool "Unredacted Notifications" is not set to "Disallow", or on the Samsung Android device "Notifications" menu is not disabled, this is a finding.

Fix: F-90904r1256113_fix

Configure the Samsung Android devices to not display (work environment) notifications when the device is locked. On the management tool, in the work profile restrictions section, set "Unredacted Notifications" to "Disallow".

c
Samsung Android 17 must be configured to enable encryption for data at rest on removable storage media or, alternately, the use of removable storage media must be disabled.
SC-28 - High - CCI-001199 - V-286319 - SV-286319r1256117_rule
RMF Control
SC-28
Severity
H
CCI
CCI-001199
Version
KNOX-17-006300
Vuln IDs
  • V-286319
Rule IDs
  • SV-286319r1256117_rule
The MOS must ensure the data being written to the mobile device's removable media is protected from unauthorized access. If data at rest is unencrypted, it is vulnerable to disclosure. Even if the operating system enforces permissions on data access, an adversary can read removable media directly, thereby circumventing operating system controls. Encrypting the data ensures confidentiality is protected even when the operating system is not running. SFR ID: FMT_SMF_EXT.1.1 #20, #47d
Checks: C-91001r1256115_chk

Review the configuration to determine if the Samsung Android devices are either enabling data at rest protection for removable media or disabling their use. This requirement is not applicable for devices that do not support removable storage media. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device restrictions, verify "Mount physical media" is set to "Disallow". On the Samsung Android device, verify that a microSD card cannot be mounted. The device should ignore the inserted SD card and no notifications for the transfer of media files should appear, nor should any files be listed using a file browser, such as Samsung My Files. If on the management tool "Mount physical media" is not set to "Disallow", or on the Samsung Android device a microSD card can be mounted, this is a finding.

Fix: F-90906r1256116_fix

Configure the Samsung Android devices to enable data at rest protection for removable media, or alternatively, disable their use. This requirement is not applicable for devices that do not support removable storage media. On the management tool, in the device restrictions, set "Mount physical media" to "Disallow". This disables the use of all removable storage, e.g., microSD cards, USB thumb drives, etc. If the deployment requires the use of microSD cards, Knox Platform for Enterprise (KPE) can be used to allow them in a STIG-approved configuration. In this case, do not configure this policy, and instead replace with KPE policy (innately by the management tool or via Knox Service Plugin [KSP]) "Enforce external storage encryption" with value "enable".

b
Samsung Android 17 must be configured to disable authentication mechanisms providing user access to protected data other than a password authentication factor: Face authentication factor (unless NIAP-validated).
IA-2 - Medium - CCI-000765 - V-286320 - SV-286320r1256773_rule
RMF Control
IA-2
Severity
M
CCI
CCI-000765
Version
KNOX-17-006400
Vuln IDs
  • V-286320
Rule IDs
  • SV-286320r1256773_rule
Note: This requirement is not applicable for specific biometric authentication factors included in the product's Common Criteria evaluation. The biometric factor can be used to authenticate the user to unlock the mobile device. Unapproved/evaluated biometric mechanisms could allow unauthorized users to have access to DoW sensitive data if compromised. By not permitting the use of unapproved/evaluated biometric authentication mechanisms, this risk is mitigated. SFR ID: FMT_SMF_EXT.1.1 #22, FIA_UAU.5.1
Checks: C-91002r1256232_chk

Note: This requirement is not applicable for specific biometric authentication factors included in the product's Common Criteria evaluation. Review the configuration to determine if the Samsung Android devices are disabling face recognition. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool in the device restrictions, verify "face recognition" is set to "disable". On the Samsung Android device: 1. Open Settings >> Lock screen and AOD >> Screen lock and biometrics. 2. Enter current password. 3. Open "Face recognition" and, if required, register a face. 4. Verify the "face unlock" option is disabled and cannot be enabled. If on the management tool "face recognition" is not set to "disable", or on the Samsung Android device "face unlock" can be enabled, this is a finding.

Fix: F-90907r1256233_fix

Note: This requirement is not applicable for specific biometric authentication factors included in the product's Common Criteria evaluation. Configure the Samsung Android devices to disable face recognition. On the management tool, in the device restrictions, set "face recognition" to "disable".

b
Samsung Android 17 must be configured to disable developer modes.
CM-7 - Medium - CCI-000381 - V-286323 - SV-286323r1256236_rule
RMF Control
CM-7
Severity
M
CCI
CCI-000381
Version
KNOX-17-006700
Vuln IDs
  • V-286323
Rule IDs
  • SV-286323r1256236_rule
Developer modes expose features of the MOS that are not available during standard operation. An adversary may leverage a vulnerability inherent in a developer mode to compromise the confidentiality, integrity, and availability of DoW sensitive information. Disabling developer modes mitigates this risk. SFR ID: FMT_SMF_EXT.1.1 #26
Checks: C-91005r1256235_chk

Review the configuration to determine if the Samsung Android devices are disabling developer modes. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device restrictions, verify "Debugging Features" is set to "Disallow". On the Samsung Android device: 1. Open Settings >> About phone >> Software information. 2. Tap on the Build Number to try to enable "Developer Options" and validate that action is blocked. If on the management tool "Debugging Features" is not set to "Disallow" or on the Samsung Android device "Developer Options" action is not blocked, this is a finding.

Fix: F-90910r1256124_fix

Configure the Samsung Android devices to disable developer modes. On the management tool, in the device restrictions, set "Debugging Features" to "Disallow".

b
The Samsung Android 17 work profile must be configured to enable audit logging.
AU-6 - Medium - CCI-000154 - V-286325 - SV-286325r1256128_rule
RMF Control
AU-6
Severity
M
CCI
CCI-000154
Version
KNOX-17-006900
Vuln IDs
  • V-286325
Rule IDs
  • SV-286325r1256128_rule
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. For audit logs to be useful, administrators must have the ability to view the audit logs. SFR ID: FMT_SMF_EXT.1.1 #32
Checks: C-91007r1256126_chk

COPE: Review the configuration to determine if the Samsung Android device's work profile is enabling audit logging. This validation procedure is performed on the management tool only. On the management tool, in the Work profile restrictions, verify "Security logging" is set to "Enable". If on the management tool "Security logging" is not set to "Enable", this is a finding. COBO: Review the configuration to determine if the Samsung Android device is enabling audit logging. This validation procedure is performed on the management tool only. On the management tool, in the device restrictions, verify "Security logging" is set to "Enable". If on the management tool "Security logging" is not set to "Enable", this is a finding.

Fix: F-90912r1256127_fix

Configure the Samsung Android device's work profile to enable audit logging (COPE). Configure the Samsung Android devices to enable audit logging (COBO). On the management tool, in the work profile restrictions section, set "Security logging" to "Enable".

a
Samsung Android 17 must be configured to display the DoW advisory warning message at startup or each time the user unlocks the device.
AC-8 - Low - CCI-000048 - V-286327 - SV-286327r1256237_rule
RMF Control
AC-8
Severity
L
CCI
CCI-000048
Version
KNOX-17-007100
Vuln IDs
  • V-286327
Rule IDs
  • SV-286327r1256237_rule
Before granting access to the system, the mobile operating system is required to display the DoW-approved system use notification message or banner that provides privacy and security notices consistent with applicable Federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. Required banners help ensure that DoW can audit and monitor the activities of mobile device users without legal restriction. System use notification messages can be displayed when individuals first access or unlock the mobile device. The banner must be implemented as a "click-through" banner at device unlock (to the extent permitted by the operating system). A "click-through" banner prevents further activity on the information system unless and until the user executes a positive action to manifest agreement by clicking on a box indicating "OK." The approved DoW text must be used exactly as required in the Knowledge Service referenced in DODI 8500.01. For devices accommodating banners of 1300 characters, the banner text is: You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details. For devices with severe character limitations, the banner text is: I've read & consent to terms in IS user agreem't. The administrator must configure the banner text exactly as written without any changes. SFR ID: FMT_SMF_EXT.1.1 #36
Checks: C-91009r1256130_chk

Confirm if Method #1 or #2 is used at the Samsung device site and follow the appropriate procedure. This validation procedure is performed on both the management tool and the Samsung Android device. Validation procedure for Method #1: Place the DoW warning banner in the user agreement signed by each Samsung Android device user. Review the signed user agreements for several Samsung Android device users and verify the agreement includes the required DoW warning banner text. Validation procedure for Method #2 (preferred method): Configure the warning banner text in the lock screen message on each managed mobile device. On the management tool, in the device restrictions section, verify "Lock Screen Message" is set to the DoW-mandated warning banner text. On the Samsung Android device, verify the required DoW warning banner text is displayed on the lock screen. If the warning text has not been placed in the signed user agreement, or if on the management tool "Lock Screen Message" is not set to the DoW-mandated warning banner text, or on the Samsung Android device the required DoW warning banner text is not displayed on the lock screen, this is a finding.

Fix: F-90914r1256131_fix

Configure the DoW warning banner by either of the following methods (required text is found in the Vulnerability Description): Method #1: Place the DoW warning banner in the user agreement signed by each Samsung Android device user. Method #2 (preferred method): Configure the warning banner text in the Lock screen message on each managed mobile device. On the management tool, in the device restrictions section, set "Lock Screen Message" to the DoW-mandated warning banner text.

b
Samsung Android 17 must be configured to disable USB mass storage mode.
SC-41 - Medium - CCI-002546 - V-286329 - SV-286329r1256136_rule
RMF Control
SC-41
Severity
M
CCI
CCI-002546
Version
KNOX-17-007300
Vuln IDs
  • V-286329
Rule IDs
  • SV-286329r1256136_rule
USB mass storage mode enables the transfer of data and software from one device to another. This software can include malware. When USB mass storage is enabled on a mobile device, it becomes a potential vector for malware and unauthorized data exfiltration. Prohibiting USB mass storage mode mitigates this risk. SFR ID: FMT_SMF_EXT.1.1 #39
Checks: C-91011r1256134_chk

Review the configuration to determine if the Samsung Android device is disabling USB mass storage mode. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device restrictions, verify "USB file transfer" has been set to "Disallow". On the Samsung Android device, from the "USB for charging phone" notification, verify that "Transferring files/Android Auto" and "Transferring images" are not options. If on the management tool "USB file transfer" is not set to "Disallow", or on the Samsung Android device "Transferring files/Android Auto" or "Transferring images" options are available, this is a finding.

Fix: F-90916r1256135_fix

Configure the Samsung Android device to disable USB mass storage mode. On the management tool, in the device restrictions, set "USB file transfer" to "Disallow". DeX drag and drop file transfer capabilities will be prohibited, but all other DeX capabilities remain usable.

b
Samsung Android 17 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.
SC-4 - Medium - CCI-001090 - V-286330 - SV-286330r1256138_rule
RMF Control
SC-4
Severity
M
CCI
CCI-001090
Version
KNOX-17-007400
Vuln IDs
  • V-286330
Rule IDs
  • SV-286330r1256138_rule
Data on mobile devices is protected by numerous mechanisms, including user authentication, access control, and cryptography. When the data is backed up to an external system (either locally connected or cloud based), many, if not all, of these mechanisms are no longer present. This leaves the backed-up data vulnerable to attack. Disabling backup to external systems mitigates this risk. SFR ID: FMT_SMF_EXT.1.1 #40
Checks: C-91012r1256137_chk

Verify requirement KNOX-17-007300 (disallow USB file transfer) has been implemented. If "Disallow USB file transfer" has not been implemented, this is a finding.

Fix: F-90917r1255639_fix

Ensure "USB file transfer" has been disallowed (refer to requirement KNOX-17-007300).

b
Samsung Android 17 must be configured to not allow backup of [all applications, configuration data] to remote systems. (This requirement applies to the work profile for COPE.) - Disable Data Sync Framework.
SC-4 - Medium - CCI-001090 - V-286331 - SV-286331r1256140_rule
RMF Control
SC-4
Severity
M
CCI
CCI-001090
Version
KNOX-17-007500
Vuln IDs
  • V-286331
Rule IDs
  • SV-286331r1256140_rule
Backups to remote systems (including cloud backup) can leave data vulnerable to breach on the external systems, which often offer less protection than the MOS. Where the remote backup involves a cloud-based solution, the backup capability is often used to synchronize data across multiple devices. In this case, DoW devices may synchronize DoW sensitive information to a user's personal device or other unauthorized computers that are vulnerable to breach. Disallowing remote backup mitigates this risk. SFR ID: FMT_SMF_EXT.1.1 #40
Checks: C-91013r1256139_chk

Verify requirement KNOX-17-009100 (disallow modify accounts) has been implemented. If "disallow modify accounts" has not been implemented, this is a finding.

Fix: F-90918r1255642_fix

Disallow modify accounts (refer to requirement KNOX-17-009100).

b
Samsung Android 17 must be configured to not allow backup of all applications and configuration data to remote systems. - Disable Backup Services.
SC-4 - Medium - CCI-001090 - V-286332 - SV-286332r1256143_rule
RMF Control
SC-4
Severity
M
CCI
CCI-001090
Version
KNOX-17-007600
Vuln IDs
  • V-286332
Rule IDs
  • SV-286332r1256143_rule
Backups to remote systems (including cloud backup) can leave data vulnerable to breach on the external systems, which often offer less protection than the MOS. Where the remote backup involves a cloud-based solution, the backup capability is often used to synchronize data across multiple devices. In this case, DoW devices may synchronize DoW sensitive information to a user's personal device or other unauthorized computers that are vulnerable to breach. Disallowing remote backup mitigates this risk. SFR ID: FMT_SMF_EXT.1.1 #40
Checks: C-91014r1256141_chk

Review the configuration to determine if the Samsung Android devices are disabling backup to remote systems (including commercial clouds). This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device restrictions section, verify "Backup service" is set to "Disable". On the Samsung Android device: 1. Open Settings >> Accounts and backup. 2. Verify any backup service listed cannot be configured to back up data. If on the management tool "Backup service" is not set to "Disable", or on the Samsung Android device a listed backup service can be configured to back up data, this is a finding.

Fix: F-90919r1256142_fix

Configure the Samsung Android devices to disable backup to remote systems (including commercial clouds). On the management tool, in the device restrictions, set "Backup service" to "Disable".

b
Samsung Android 17 must be configured to enable authentication of personal hotspot connections to the device using a preshared key.
AC-18 - Medium - CCI-001443 - V-286334 - SV-286334r1256433_rule
RMF Control
AC-18
Severity
M
CCI
CCI-001443
Version
KNOX-17-007800
Vuln IDs
  • V-286334
Rule IDs
  • SV-286334r1256433_rule
If no authentication is required to establish personal hotspot connections (Wi-Fi and Bluetooth), an adversary may be able to use that device to perform attacks on other devices or networks without detection. A sophisticated adversary may also be able to exploit unknown system vulnerabilities to access information and computing resources on the device. Requiring authentication to establish personal hotspot connections mitigates this risk. Application note: If hotspot functionality is permitted, it must be authenticated via a preshared key. There is no requirement to enable hotspot functionality, and it is recommended this functionality be disabled by default. SFR ID: FMT_SMF_EXT.1.1 #41
Checks: C-91016r1256432_chk

This is a "User-Based Enforcement (UBE)" control. Check a sample of Samsung phones at the site and verify the Wi-Fi hotspot preshared key (password) is set to "WPA3-Personal". 1. Navigate to Settings >> Connections >> Mobile Hotspot and Tethering. 2. Tap on "Mobile Hotspot". 3. Tap on the "Network name" field to bring up the configuration options. 4. Click on the "Security" link and select "WPA3-Personal". If the Wi-Fi hotspot security is not set to "WPA3-Personal", this is a finding.

Fix: F-90921r1256239_fix

This is a "User-Based Enforcement (UBE)" control. Train users to not change the default Wi-Fi hotspot security setting: 15-character complex Wi-Fi hotspot preshared key (password) ("WPA3-Personal"). (KNOX-17-009300) If the required preshared key is not set up, train users to use the following procedure to set up the required setting: 1. Navigate to Settings >> Connections >> Mobile Hotspot and Tethering. 2. Tap on "Mobile Hotspot". 3. Tap on the "Network name" field to bring up the configuration options. 4. Click on the "Security" link and select "WPA3-Personal".

a
Samsung Android 17 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile).
CM-7 - Low - CCI-000381 - V-286339 - SV-286339r1256446_rule
RMF Control
CM-7
Severity
L
CCI
CCI-000381
Version
KNOX-17-008400
Vuln IDs
  • V-286339
Rule IDs
  • SV-286339r1256446_rule
Some Bluetooth profiles provide the capability for remote transfer of sensitive DoW data without encryption or otherwise do not meet DoW IT security policies and therefore must be disabled. SFR ID: FMT_SMF_EXT.1.1/BLUETOOTH BT-8
Checks: C-91021r1256149_chk

Review the Samsung documentation and inspect the configuration to verify the Samsung Android devices are paired only with devices that support HSP, HFP, SPP, A2DP, AVRCP, and PBAP Bluetooth profiles. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device restrictions section, verify "Bluetooth" is set to the authorizing official (AO)-approved selection: "Allow" if the AO has approved the use of Bluetooth or "Disallow" if the AO has not approved its use. On the Samsung Android device: 1. Open Settings >> Connections >> Bluetooth. 2. Verify all listed paired Bluetooth devices use only authorized Bluetooth profiles. If on the management tool "Bluetooth" is not set to the AO-approved value, or the Samsung Android device is paired with a device that uses unauthorized Bluetooth profiles, this is a finding.

Fix: F-90926r1256445_fix

Configure the Samsung Android devices to disable Bluetooth, or if the AO has approved the use of Bluetooth (for example, for hands-free use), train users to only pair devices that support HSP, HFP, SPP, A2DP, AVRCP, and PBAP profiles. On the management tool, in the device restrictions section, set "Bluetooth" to the AO-approved selection: "Allow" if the AO has approved the use of Bluetooth or "Disallow" if the AO has not approved its use. The user training requirement is satisfied in requirement KNOX-16-009400. If a COBO deployment requires the use of specific Bluetooth profiles, Knox Platform for Enterprise (KPE) can be used to allow them in a STIG-approved configuration. In this case, do not configure this policy, and instead replace with KPE policy (innately by the management tool or via Knox Service Plugin [KSP]) "Add Bluetooth UUIDs To WhiteList" with values "HSP_UUID, HFP_UUID, SPP_UUID, A2DP_ADVAUDIODIST_UUID, AVRCP_CONTROLLER_UUID, AVRCP_TARGET_UUID" and default deny list as "enable".

b
Samsung Android 17 must be configured to disable ad hoc wireless client-to-client connection capability.
SC-40 - Medium - CCI-002536 - V-286340 - SV-286340r1256154_rule
RMF Control
SC-40
Severity
M
CCI
CCI-002536
Version
KNOX-17-008500
Vuln IDs
  • V-286340
Rule IDs
  • SV-286340r1256154_rule
Ad hoc wireless client-to-client connections allow mobile devices to communicate with each other directly, circumventing network security policies and making the traffic invisible. This could allow the exposure of sensitive DoW data and increase the risk of downloading and installing malware of the DoW mobile device. SFR ID: FMT_SMF_EXT.1.1 WL-5/PP-Module for WLAN Clients
Checks: C-91022r1256152_chk

Review the configuration to determine if the Samsung Android devices are disallowing Wi-Fi Direct. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the user restrictions, verify "Wi-Fi Direct" has been set to "Disallow". On the Samsung Android device: 1. Open Settings >> Connections >> Wi-Fi. 2. From the hamburger menu, select Wi-Fi Direct. 3. Verify that Wi-Fi Direct cannot be selected. If on the management tool "Wi-Fi Direct" is not set to "Disallow", or on the Samsung Android device a Wi-Fi direct device is listed that can be connected to, this is a finding.

Fix: F-90927r1256153_fix

Configure the Samsung Android devices to disallow Wi-Fi Direct. On the management tool, in the user restrictions, set "Wi-Fi Direct" to "Disallow". Wi-Fi direct connections and pairing between devices will become unavailable.

b
Samsung Android must be enrolled as a COBO device.
CM-6 - Medium - CCI-000366 - V-286342 - SV-286342r1256157_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-008700
Vuln IDs
  • V-286342
Rule IDs
  • SV-286342r1256157_rule
The device is the designated application group for the COBO use case. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91024r1256155_chk

Review the configuration to determine if the Samsung Android devices are enrolled in a DoW-approved use case. This validation procedure is performed on both the management tool administration console and the Samsung Android device. On the management tool, verify the default enrollment is set as "fully managed". On the Samsung Android device: 1. Open Settings >> Security and privacy >> More security settings >> Device admin apps. 2. Verify the management tool agent is listed. If on the management tool the default enrollment is not set as "Fully managed" or the management tool agent is not listed, this is a finding.

Fix: F-90929r1256156_fix

Enroll the Samsung Android devices in a DoW-approved use case. On the management tool, configure the default enrollment as "Fully managed". Refer to the management tool documentation to determine how to configure the device enrollment.

b
Samsung Android must be configured to disallow configuration of the device's date and time.
CM-6 - Medium - CCI-000366 - V-286343 - SV-286343r1256160_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-008900
Vuln IDs
  • V-286343
Rule IDs
  • SV-286343r1256160_rule
Determining the correct time a particular application event occurred on a system is critical when conducting forensic analysis and investigating system events. Periodically synchronizing internal clocks with an authoritative time source is necessary to correctly correlate the timing of events that occur across the enterprise. The three authoritative time sources for Samsung Android are an authoritative time server that is synchronized with redundant United States Naval Observatory (USNO) time servers as designated for the appropriate DoW network (NIPRNet or SIPRNet), the Global Positioning System (GPS), or the wireless carrier. Time stamps generated by the audit system in Samsung Android must include both date and time. The time may be expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91025r1256158_chk

Review the configuration to determine if the Samsung Android devices are disallowing the users from changing the date and time. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the device restrictions, verify "Configure Date/Time" is set to "Disallow". On the Samsung Android device: 1. Open Settings >> General management >> Date and time. 2. Verify "Automatic date and time" is on and the user cannot disable it. If on the management tool "Configure Date/Time" is not set to "Disallow", or on the Samsung Android device "Automatic date and time" is not set or the user can disable it, this is a finding.

Fix: F-90930r1256159_fix

Configure the Samsung Android devices to disallow users from changing the date and time. On the management tool, in the device restrictions, set "Configure Date/Time" to "Disallow".

b
Samsung Android's work profile must have the DoW root and intermediate PKI certificates installed.
CM-6 - Medium - CCI-000366 - V-286344 - SV-286344r1256776_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-009000
Vuln IDs
  • V-286344
Rule IDs
  • SV-286344r1256776_rule
DoW root and intermediate PKI certificates are used to verify the authenticity of PKI certificates of users and web services. If the root and intermediate certificates are not available, an adversary could falsely sign a certificate in such a way that it could not be detected. Providing access to the DoW root and intermediate PKI certificates greatly diminishes the risk of this attack. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91026r1256447_chk

COPE: Review the configuration to determine if the Samsung Android's work profile has the DoW root and intermediate PKI certificates installed. This validation procedure is performed on both the management tool and the Samsung Android device. The current DoW root and intermediate PKI certificates may be obtained in self-extracting zip files at https://cyber.mil/pki-pke (for NIPRNet). On the management tool, in the work profile policy management, verify the DoW root and intermediate PKI certificates are installed. On the Samsung Android device: 1. Open Settings >> Security and privacy >> More security settings >> View security certificates. 2. In the "User" tab, verify the DoW root and intermediate PKI certificates are listed in the work profile. If on the management tool the DoW root and intermediate PKI certificates are not listed in the work profile, or on the Samsung Android device the DoW root and intermediate PKI certificates are not listed in the work profile, this is a finding. COBO: Review the configuration to determine if the Samsung Android devices have the DoW root and intermediate PKI certificates installed. This validation procedure is performed on both the management tool and the Samsung Android device. The current DoW root and intermediate PKI certificates may be obtained in self-extracting zip files at https://cyber.mil/pki-pke (for NIPRNet). On the management tool, in the device policy management, verify the DoW root and intermediate PKI certificates are installed. On the Samsung Android device: 1. Open Settings >> Security and privacy >> More security settings >> View security certificates. 2. In the User tab, verify the DoW root and intermediate PKI certificates are listed in the device. If on the management tool the DoW root and intermediate PKI certificates are not listed in the device, or on the Samsung Android device the DoW root and intermediate PKI certificates are not listed in the device, this is a finding.

Fix: F-90931r1256775_fix

Install the DoW root and intermediate PKI certificates into the Samsung Android devices (install in work profile for COPE). The current DoW root and intermediate PKI certificates may be obtained in self-extracting zip files at https://cyber.mil/pki-pke (for NIPRNet). On the management tool, in the device policy management (work profile for COPE), install the DoW root and intermediate PKI certificates.

b
Samsung Android's work profile must be configured to prevent users from adding personal email accounts to the work email app.
CM-6 - Medium - CCI-000366 - V-286345 - SV-286345r1256166_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-009100
Vuln IDs
  • V-286345
Rule IDs
  • SV-286345r1256166_rule
If the user is able to add a personal email account (POP3, IMAP, EAS) to the work email app, it could be used to forward sensitive DoW data to unauthorized recipients. Restricting email account addition to the administrator or to allow listed accounts mitigates this vulnerability. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91027r1256164_chk

Review the configuration to determine if the Samsung Android devices are preventing users from adding personal email accounts to the work email app. On the management tool, in the device restrictions section, verify "Modify accounts" is set to "Disallow". COPE: On the Samsung Android device: 1. Open Settings >> Accounts and backup >> Manage accounts. 2. Navigate to the "Work" tab. 3. Verify no account can be added. COBO: On the Samsung Android device: 1. Open Settings >> Accounts and backup >> Manage accounts. 2. Verify no account can be added. If on the management tool "Modify accounts" is not set to "Disallow", or on the Samsung Android device an account can be added, this is a finding.

Fix: F-90932r1256165_fix

Configure the Samsung Android devices to prevent users from adding personal email accounts to the work email app. On the management tool, in the work profile restrictions, set "Modify accounts" to "Disallow" (COPE). On the management tool, in the device restrictions, set "Modify accounts" to "Disallow" (COBO).

a
Samsung Android's work profile must be configured to enable Common Criteria (CC) mode.
CM-6 - Low - CCI-000366 - V-286346 - SV-286346r1256169_rule
RMF Control
CM-6
Severity
L
CCI
CCI-000366
Version
KNOX-17-009200
Vuln IDs
  • V-286346
Rule IDs
  • SV-286346r1256169_rule
The CC mode feature is a superset of other features and behavioral changes that are mandatory MDFPP requirements. If CC mode is not implemented, the device will not be operating in the NIAP-certified compliant CC mode of operation. When enforcing Android Enterprise (AE) CC mode on a Samsung Android device, additional Samsung-specific security features are also enabled. CC mode implements the following behavioral/functional changes to meet MDFPP requirements: - How the Bluetooth and Wi-Fi keys are stored using different types of encryption. - Download mode is disabled and all updates will occur via Firmware Over the Air (FOTA) only. In addition, CC mode adds new restrictions not to meet MDFPP requirements, but to offer better security above what is required: - Force password info following FOTA update for consistency. - Disable Remote unlock by FindMyMobile. - Restrict biometric attempts to 10. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91028r1256167_chk

Review the configuration to determine if the Samsung Android devices are enabling CC mode. This validation procedure is performed on both the management tool and the Samsung Android device. On the management tool, in the work profile restrictions, verify "Common Criteria mode" is set to "Enable". On the Samsung Android device, put the device into "Download mode" (press and hold down the Home + Power + Volume Down buttons at the same time) and verify the text "Blocked by CC Mode" is displayed on the screen. If on the management tool "Common Criteria mode" is not set to "Enable", or on the Samsung Android device the text "Blocked by CC Mode" is not displayed in "Download mode", this is a finding.

Fix: F-90933r1256168_fix

Configure the Samsung Android devices to enable CC mode. On the management tool, in the work profile restrictions, set "Common Criteria mode" to "Enable".

b
Samsung Android device users must complete required training.
CM-6 - Medium - CCI-000366 - V-286347 - SV-286347r1256172_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-009300
Vuln IDs
  • V-286347
Rule IDs
  • SV-286347r1256172_rule
The security posture of Samsung devices requires the device user to configure several required policy rules on their device. User-Based Enforcement (UBE) is required for these controls. In addition, if the authorizing official (AO) has approved the use of an unmanaged personal space, the user must receive training on risks. If a user is not aware of their responsibilities and does not comply with UBE requirements, the security posture of the Samsung mobile device may become compromised, and DoW sensitive data may become compromised. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91029r1256170_chk

Review a sample of site User Agreements for Samsung device users or similar training records and training course content. Verify Samsung device users have completed required training. The intent is that required training is renewed on a periodic basis in a time period determined by the AO. If any Samsung device user has not completed required training, this is a finding.

Fix: F-90934r1256171_fix

Have all Samsung device users complete training on the following topics. Users should acknowledge they have reviewed training via a signed User Agreement or similar written record. Training topics: - Operational security concerns introduced by unmanaged applications/unmanaged personal space including applications using Global Positioning System (GPS) tracking. - Need to ensure no DoW data is saved to the personal space or transmitted from a personal app (for example, from personal email). - If the Purebred key management app is used, users are responsible for maintaining positive control of their credentialed device at all times. The DoW PKI certificate policy requires subscribers to maintain positive control of the devices that contain private keys and report any loss of control so the credentials can be revoked. Upon device retirement, turn-in, or reassignment, ensure a factory data reset is performed prior to device hand-off. Follow Mobility service provider decommissioning procedures as applicable. - How to configure the following UBE controls (users must configure the control) on the Samsung device: 1. Secure use of Calendar Alarm. 2. Local screen mirroring and MirrorLink procedures (authorized/not authorized for use). 3. Do not connect Samsung devices (via either DeX Station or dongle) to any DoW network via Ethernet connection. 4. Do not upload DoW contacts via smart call and caller ID services. 5. Do not configure a DoW network (work) VPN profile on any third-party VPN client installed in the personal space. 6. If Bluetooth connections are approved for mobile device, types of allowed connections (for example car hands-free, but not Bluetooth wireless keyboard). 7. How to perform a full device wipe. 8. Use default Wi-Fi hotspot password: 15-character complex Wi-Fi hotspot preshared password enabled ("WPA2/WPA3-personal"). - AO guidance on acceptable use and restrictions, if any, on downloading and installing personal apps and data (music, photos, etc.) in the Samsung device personal space.

c
The Samsung Android device must have the latest available Samsung Android operating system (OS) installed.
CM-6 - High - CCI-000366 - V-286348 - SV-286348r1256175_rule
RMF Control
CM-6
Severity
H
CCI
CCI-000366
Version
KNOX-17-009400
Vuln IDs
  • V-286348
Rule IDs
  • SV-286348r1256175_rule
Required security features are not available in earlier OS versions. In addition, earlier versions may have known vulnerabilities. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91030r1256173_chk

Review the configuration to confirm if the Samsung Android devices have the most recently released version of Samsung Android installed. This procedure is performed on both the management tool and the Samsung Android device. In the management tool management console, review the version of Samsung Android installed on a sample of managed devices. This procedure will vary depending on the management tool product. Refer to the notes below to determine the latest available OS version. On the Samsung Android device, to determine the installed OS version: 1. Open Settings. 2. Tap "About phone". 3. Tap "Software information". If the installed version of Android OS on any reviewed Samsung devices is not the latest released by the wireless carrier, this is a finding. Note: Some wireless carriers list the version of the latest Android OS release by mobile device model online: AT&T: https://www.att.com/devicehowto/dsm.html#!/popular/make/Samsung Verizon Wireless: https://www.verizonwireless.com/support/software-updates/ Google Android OS patch website: https://source.android.com/security/bulletin/ Samsung Android OS patch website: https://security.samsungmobile.com/securityUpdate.smsb

Fix: F-90935r1256174_fix

Install the latest released version of Samsung Android OS on all managed Samsung devices. Note: In most cases, OS updates are released by the wireless carrier (for example, Sprint, T-Mobile, Verizon Wireless, and AT&T).

b
The Samsung Android device must be configured to enable Certificate Revocation List (CRL) status checking.
CM-6 - Medium - CCI-000366 - V-286349 - SV-286349r1256178_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-009500
Vuln IDs
  • V-286349
Rule IDs
  • SV-286349r1256178_rule
A CRL allows a certificate issuer to revoke a certificate for any reason, including improperly issued certificates and compromise of the private keys. Checking the revocation status of the certificate mitigates the risk associated with using a compromised certificate. For this reason, users must not be able to disable this configuration. Samsung Android can control CRL checking but only using Knox APIs. Alternatively, CRL checking is based on app development best practice. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91031r1256176_chk

Review the configuration to confirm that revocation checking is enabled. Verify the revocation checklist is set to the required applications. This procedure is performed on the management tool. On the management tool: 1. Open Security Policy >> Certificates Policy >> Revocation section. 2. Select "Get CRL". 3. Verify Toast message "Get revocation check: true". If on the management tool the revocation check is disabled, this is a finding.

Fix: F-90936r1256177_fix

Configure the Samsung Android devices to enable CRL revocation checks for required applications. These revocation checks must be enabled using the Knox Platform for Enterprise (KPE) APIs. On the management tool, in the Certificate Policy restrictions, enable "Revocation Checks" for required applications.

b
The Samsung Android device must be configured to enforce that Wi-Fi sharing is disabled.
CM-6 - Medium - CCI-000366 - V-286350 - SV-286350r1256181_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-009600
Vuln IDs
  • V-286350
Rule IDs
  • SV-286350r1256181_rule
Wi-Fi sharing is an optional configuration of Wi-Fi tethering/mobile hotspot, which allows the device to share its Wi-Fi connection with other wirelessly connected devices instead of its mobile (cellular) connection. Wi-Fi sharing grants the "other" device access to a corporate Wi-Fi network and may possibly bypass the network access control mechanisms. This risk can be partially mitigated by requiring the use of a preshared key for personal hotspots. SFR ID: FMT_SMF.1.1 #47
Checks: C-91032r1256179_chk

Review device configuration settings to confirm Wi-Fi sharing is disabled. Mobile hotspot must be enabled to enable Wi-Fi sharing. If the authorizing official (AO) has not approved mobile hotspot, and it has been verified as disabled on the EMM console, no further action is needed. If mobile hotspot is being used, use the following procedure to verify Wi-Fi sharing is disabled. This is a "User-Based Enforcement (UBE)" control. Check a sample of Samsung phones at the site and verify that the mobile hotspot Wi-Fi sharing option is toggled to off: 1. Navigate to Settings >> Connections >> Mobile Hotspot and Tethering >> Mobile Hotspot. 2. Tap "Network name". 3. Tap "Advanced". 4. Verify that "Wi-Fi sharing" is toggled off or the option is disabled. If the Wi-Fi sharing is not set to disabled, this is a finding. On the EMM console: COBO: 1. Open "Set user restrictions". 2. Verify "Disallow sharing admin configured Wi-Fi" is toggled to "ON". COPE: 1. Open "Set user restrictions on parent". 2. Verify "Disallow sharing admin configured Wi-Fi" it toggled to "ON". If on the EMM console, "Disallow sharing admin configured Wi-Fi" is not enabled, this is a finding.

Fix: F-90937r1256180_fix

Configure the Samsung Android 17 device to disable Wi-Fi sharing. Mobile hotspot must be enabled to enable Wi-Fi sharing. If the AO has not approved mobile hotspot, and it has been disabled on the EMM console, no further action is needed. If mobile hotspot is being used, then use the following procedure and "User-Based Enforcement (UBE)" control: Train users to disable/not enable Samsung Wi-Fi sharing. Refer to STIG requirement KNOX-17-009300. 1. Navigate to Settings >> Connections >> Mobile Hotspot and Tethering >> Mobile Hotspot. 2. Tap "Network name". 3. Tap "Advanced". 4. Verify that "Wi-Fi sharing" is toggled off or the option is disabled. On the EMM console: COBO: 1. Open "Set user restrictions". 2. Toggle "Disallow sharing admin configured Wi-Fi" to "ON". COPE: 1. Open "Set user restrictions on parent". 2. Toggle "Disallow sharing admin configured Wi-Fi" to "ON". On COBO devices, Knox Platform for Enterprise (KPE) policy can be used to configure this setting without "User-Based Enforcement (UBE)" control, by setting the "Allow Wi-Fi sharing" option in KSP to disable.

b
The Samsung Android device work profile must be configured to enforce the system application disable list.
CM-6 - Medium - CCI-000366 - V-286351 - SV-286351r1256184_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-009700
Vuln IDs
  • V-286351
Rule IDs
  • SV-286351r1256184_rule
The system application disable list controls user access to/execution of all core and preinstalled applications. Core application: Any application integrated into Samsung Android 17 by Samsung. Preinstalled application: Additional noncore applications included in the Samsung Android 17 build by Samsung or the wireless carrier. Some system applications can compromise DoW data or upload users' information to non-DoW-approved servers. A user must be blocked from using such applications that exhibit behavior that can result in compromise of DoW data or DoW user information. The site administrator must analyze all preinstalled applications on the device and disable all applications not approved for DoW use by configuring the system application disable list. SFR ID: FMT_SMF.1.1 #47
Checks: C-91033r1256182_chk

Review the configuration to confirm the system application disable list is enforced. This setting is enforced by default. Verify only approved system apps have been placed on the core allow list. This procedure is performed on the management tool. Review the system app allow list and verify only approved apps are on the list. On the management tool, in the Apps management section, select "Unhide apps" and verify the names of the apps listed. If on the management tool the system app allow list contains unapproved core apps, this is a finding.

Fix: F-90938r1256183_fix

Configure the Samsung Android 17 device to enforce the system application disable list. The required configuration is the default configuration when the device is enrolled. If the device configuration is changed, use the following procedure to bring the device back into compliance: On the management tool: 1. Open "Apps management" section. 2. Select "Hide apps". 3. Enter names of apps to hide. Configure a list of approved Samsung core and preinstalled apps in the core app allow list.

a
The Samsung Android device must be configured to disable the use of third-party keyboards.
CM-6 - Low - CCI-000366 - V-286352 - SV-286352r1256187_rule
RMF Control
CM-6
Severity
L
CCI
CCI-000366
Version
KNOX-17-010100
Vuln IDs
  • V-286352
Rule IDs
  • SV-286352r1256187_rule
Many third-party keyboard applications are known to contain malware. SFR ID: FMT_SMF.1.1 #47
Checks: C-91034r1256185_chk

Review the managed Samsung device configuration settings to confirm that no third-party keyboards are enabled. This procedure is performed on the management tool. On the management tool: 1. Open "Input methods". 2. Tap "Set input methods". 3. Verify only the approved keyboards are selected. If third-party keyboards are allowed, this is a finding.

Fix: F-90939r1256186_fix

Configure the Samsung device to disallow the use of third-party keyboards. On the management tool: 1. Open "Input methods". 2. Tap "Set input methods". 3. Select only the approved keyboard. Additionally, administrators can configure application allow lists for Google Play that do not have any third-party keyboards for user installation.

b
The Samsung Android device must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].
AC-6 - Medium - CCI-002235 - V-286353 - SV-286353r1256190_rule
RMF Control
AC-6
Severity
M
CCI
CCI-002235
Version
KNOX-17-010200
Vuln IDs
  • V-286353
Rule IDs
  • SV-286353r1256190_rule
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoW information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DoW sensitive information. SFR ID: FMT_MOF_EXT.1.2 #24
Checks: C-91035r1256188_chk

Review the device configuration to confirm the USB port is disabled except for charging the device. On the management tool: Verify "Disallow USB file transfer" is toggled to "OFF". If on the management tool the USB port is not disabled, this is a finding.

Fix: F-90940r1256189_fix

Configure the Samsung device to disable the USB port (except for charging the device). On the management tool: Toggle "Disallow USB file transfer" to "OFF".

a
The Samsung Android device must be configured to perform the following management function: Disable Phone Hub.
SC-4 - Low - CCI-001090 - V-286354 - SV-286354r1256777_rule
RMF Control
SC-4
Severity
L
CCI
CCI-001090
Version
KNOX-17-010300
Vuln IDs
  • V-286354
Rule IDs
  • SV-286354r1256777_rule
It may be possible to transfer work profile data on a DoW Android device to an unauthorized Chromebook if the user has the same Google account set up on the Chromebook. This may result in the exposure of sensitive DoW data. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91036r1256241_chk

Review the management tool to confirm Phone Hub has been disabled. On the management tool: 1. Open "Nearby notification streaming policy". 2. Verify "Nearby notification streaming policy" is set to "Disabled". 3. Open "Nearby app streaming policy". 4. Verify "Nearby app streaming policy" is set to "Disabled". If on the management tool the "Nearby Streaming Policy" is not set to "Disabled", this is a finding. Note: From a Chromebook, if a device is connected to the Phone Hub, try to set up the notifications. It will fail to connect to the device to complete the setup if Phone Hub has been disabled on the DoW Android device.

Fix: F-90941r1256242_fix

Configure the Samsung device to disable the nearby notification and app streaming policy to disable Phone Hub. On the management tool: 1. Open "Nearby notification streaming policy". 2. Set "Nearby notification streaming policy" to "Disabled". 3. Open "Nearby app streaming policy". 4. Set "Nearby app streaming policy" to "Disabled".

b
Samsung Android 17 must disable the ability of the user to wipe the device.
CM-6 - Medium - CCI-000366 - V-286355 - SV-286355r1256196_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-010400
Vuln IDs
  • V-286355
Rule IDs
  • SV-286355r1256196_rule
This feature must be disabled in order to comply with DoW electronic records retention requirements for mobile devices. Otherwise, mobile device users could wipe the device, which would violate DoW policy. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91037r1256194_chk

Review configuration settings to confirm the user is unable to perform a factory reset and the admin has the ability to inject a recovery account on the device to unlock Factory Reset Protection (FRP). This check procedure is performed on the device management tool and the Samsung Android 17 device. On the MDM console: Verify factory reset configuration. COBO procedures: 1. Open user restrictions. 2. Verify "Disallow Factory Reset" is enabled. Verify factory reset protection policy configuration. 1. From the Android Enterprise policy management, go to the Factory Reset Protection section. 2. Verify "Factory Reset Protection" is set to "Allow/Enabled". 3. Verify the correct Google Account ID(s) is/are listed as allowed to unlock the FRP. On the managed Samsung Android 17 device, verify factory reset configuration. COBO: 1. Open Settings >> General management >> Reset. 2. Tap the "Factory data reset" option. 3. Verify the "Action not allowed" pop up appears and that the factory data reset does not proceed. If the Android device user is able to perform a factory reset or the admin cannot unlock the Android phone after an FRP event, this is a finding.

Fix: F-90942r1256195_fix

Configure Samsung Android 17 device to disable the ability of the user from wiping the Android device. In addition, enable the admin to inject a recovery account on the device so they can unlock FRP. On the MDM console, do the following: COBO procedures – disallow factory reset: 1. Open user restrictions. 2. Enable "Disallow Factory Reset". COBO procedures – set factory reset protection policy: 1. Select Device owner management >> Set factory reset protection. 2. From the "Accounts" section, go to Add Account >> Enter recovery account, then press "Ok". 3. From the "Enabled" section, select "Enabled" to enable factory reset protection policy. 4. Press "Save" to confirm all changes. API: addUserRestriction, DISALLOW_FACTORY_RESET and setFactoryResetProtectionPolicy

a
Samsung Android 17 must disable wireless printing.
CM-6 - Low - CCI-000366 - V-286356 - SV-286356r1256199_rule
RMF Control
CM-6
Severity
L
CCI
CCI-000366
Version
KNOX-17-010700
Vuln IDs
  • V-286356
Rule IDs
  • SV-286356r1256199_rule
Wireless printing allows the printing of sensitive DoW documents to non-DoW controlled printers, which may lead to the exposure of sensitive DoW information. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91038r1256197_chk

Review configuration settings to confirm wireless printing has been disabled. This check procedure is performed on the device management tool and the Samsung Android 17 device. On the MDM console: COBO/COPE procedures: 1. Open user restrictions. 2. Verify that "Disallow printing" is enabled. On the managed Samsung Android 17 device: COBO/COPE procedures: 1. Open a document or image from the file app and try to print. 2. Verify that the document/image does not print. If wireless printing has not been disabled, this is a finding.

Fix: F-90943r1256198_fix

Configure Samsung Android 17 device to disable wireless printing. On the MDM console, do the following: COBO procedures: 1. Open user restrictions. 2. Enable "Disallow printing". COPE procedures: 1. Open user restrictions. 2. Enable "Disallow printing".

a
Samsung Android 17 must disable screen capture.
CM-6 - Low - CCI-000366 - V-286357 - SV-286357r1256202_rule
RMF Control
CM-6
Severity
L
CCI
CCI-000366
Version
KNOX-17-010800
Vuln IDs
  • V-286357
Rule IDs
  • SV-286357r1256202_rule
The feature screen capture could lead to the exposure of sensitive DoW information. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91039r1256200_chk

Review configuration settings to confirm screen capture has been disabled. This check procedure is performed on the device management tool and the Samsung Android 17 device. On the MDM console: COBO/COPE procedures: 1. Open Camera, screen capture, and audio section. 2. Verify that "Disable Screen Capture" setting is enabled. On the managed Samsung Android 17 device: COBO: 1. Press the power button and the volume down button at the same time. Verify that the message "Taking screenshots is blocked by your admin" is displayed. COPE: 1. Open a work profile app. 2. Press the power button and the volume down button at the same time. Verify that the message "Taking screenshots is blocked by your admin" is displayed. If screen capture has not been disabled, this is a finding.

Fix: F-90944r1256201_fix

Configure Samsung Android 17 to disable screen capture. On the MDM console, do the following: COBO procedures: 1. Open Camera, screen capture, and audio section. 2. Enable the "Disable Screen Capture" setting. COPE procedures: 1. Open Camera, screen capture, and audio section. 2. Enable the "Disable Screen Capture" setting.

b
Samsung Android 17 devices must have a Mobile Threat Detection (MTD) app installed.
CM-6 - Medium - CCI-000366 - V-286358 - SV-286358r1256450_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-010900
Vuln IDs
  • V-286358
Rule IDs
  • SV-286358r1256450_rule
DoW mobile devices are in constant risk of cyber threats. Mobile Threat Detection (MTD) apps mitigate these risks by providing real-time threat detection, malware prevention, and vulnerability analysis. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91040r1256449_chk

Confirm a MTD app is installed on managed Samsung Android devices. This check procedure is performed on both the device management tool and the Samsung Android device. In the MDM console, verify a MTD app is listed as a managed app being deployed to site managed devices. On the Samsung Android device: 1. Open the Settings app. 2. Tap "Apps" then "See all apps". 3. Verify an MTD app is listed. If a MTD app is not installed on the device, this is a finding.

Fix: F-90945r1256434_fix

Install an MTD app on managed Samsung Android devices.

b
Samsung Android 17 must implement the management setting: Disable camera.
CM-6 - Medium - CCI-000366 - V-286359 - SV-286359r1256452_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-011000
Vuln IDs
  • V-286359
Rule IDs
  • SV-286359r1256452_rule
Authorizing official (AO) approval is required before the mobile device camera can be enabled for a specific user or group of users, based on a risk assessment of the operational environment. Camera use may lead to the exposure of sensitive DoW information in some operational environments. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91041r1256451_chk

Determine if the site AO has approved the use of device cameras. Look for a document showing approval for a specific user or group of users. If not approved, review configuration settings to confirm "Allow Camera" is disabled. If approved, this requirement is not applicable. Review configuration settings to confirm the device camera has been disabled. This check procedure is performed on the device management tool and the Samsung Android 17 device. On the MDM console: COBO/COPE procedures: 1. Open camera. 2. Verify the "disable camera" setting is disabled. On the managed Samsung Android 17 device: COBO and COPE: 1. Verify the camera cannot be used on the mobile device. If the device camera has not been disabled, this is a finding.

Fix: F-90946r1256247_fix

If the AO has not approved the use of device camera, configure Samsung Android 17 to disable the device camera. On the MDM console, do the following: COBO/COPE procedures: 1. Open camera. 2. Select "Disable camera".

b
The Samsung Android device must be configured to disable Wi-Fi Aware for work profile apps.
CM-6 - Medium - CCI-000366 - V-286360 - SV-286360r1256210_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-011200
Vuln IDs
  • V-286360
Rule IDs
  • SV-286360r1256210_rule
Wi-Fi Aware allows direct connections between nearby devices for fast data transfer, video streaming, and multiplayer gaming. It allows full peer-to-peer device discovery and communication where two or more devices are publishing and/or subscribing to the same known service name. There is risk that sensitive DoW information could be transferred from a DoW mobile device to a non-DoW device or from work profile apps on a DoW device to Personal Profile apps on a non-DoW device. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91042r1256208_chk

Review device configuration settings to confirm Wi-Fi Aware is disabled for each work profile app. This procedure is performed on the EMM console. For each work profile app, verify the app is configured to deny the NEARBY_WIFI_DEVICE permission. Note: Not all apps will support Wi-Fi Aware and have the NEARBY_WIFI_DEVICE permission. If on the EMM console, the NEARBY_WIFI_DEVICE permission is not set to "deny" for all work profile apps that support Wi-Fi Aware, this is a finding.

Fix: F-90947r1256209_fix

Configure the Samsung Android 17 device to disable Wi-Fi Aware for all work profile apps. On the EMM console: For each work profile app, configure the NEARBY_WIFI_DEVICE permission to "deny" to block the use of Wi-Fi Aware, if the app supports this feature. If the app does not support Wi-Fi Aware, there may not be a NEARBY_WIFI_DEVICE permission available.

b
The Samsung Android 17 device must be configured to disable Cross-Device Handoff (also called "Continuity On").
CM-6 - Medium - CCI-000366 - V-286361 - SV-286361r1256213_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-011300
Vuln IDs
  • V-286361
Rule IDs
  • SV-286361r1256213_rule
Cross-Device Handoff (also called "Continuity On") permits a user of an Android phone to transition user activities from one device to another. Handoff passes sufficient information between the devices to describe the activity, but app data synchronization associated with the activity is handled though the cloud, which should be disabled on compliant Android devices. If a user associates both DoW and personal devices to the same Google account, the user may improperly reveal information about the nature of the user's activities on an unprotected device. Disabling Cross-Device Handoff mitigates this risk. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-91043r1256211_chk

Review device configuration settings to disable Cross-Device Handoff (also called "Continuity On"). This procedure is performed on the EMM console. Verify "TASK_CONTINUITY_HANDOFF_DISABLED" is enabled. If on the EMM console Cross-Device Handoff is not disabled, this is a finding.

Fix: F-90948r1256212_fix

Configure the Samsung Android 17 device to disable Cross-Device Handoff (also called "Continuity On"). On the EMM console: COBO and COPE: 1. Open user restrictions. 2. Enable "TASK_CONTINUITY_HANDOFF_DISABLED". API: TASK_CONTINUITY_HANDOFF_DISABLED

b
The Samsung Android 17 device must be configured to disable web-based artificial intelligence (AI) interactions.
CM-6 - Medium - CCI-000366 - V-286362 - SV-286362r1256779_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
KNOX-17-011400
Vuln IDs
  • V-286362
Rule IDs
  • SV-286362r1256779_rule
Sensitive DoW data could be exposed when an AI app processes device data in the cloud. SFR ID: FMT_SMF.1.1 #47
Checks: C-91044r1256436_chk

Verify the Samsung Android 17 device has been configured to disable web-based AI interactions. On the Android 17 phone, try to browse to unauthorized AI URLs. Examples of input include chatgpt.com, claude.ai, gemini.google.com, and v0.dev. Verify the unauthorized AI websites cannot be reached. If the Samsung Android 17 device has not been configured to disable web-based AI interactions, this is a finding.

Fix: F-90949r1256778_fix

Configure the Samsung Android 17 device to disable web-based AI interactions. For web-based AI in the browser: Create an App Configuration Policy: (Requires EMM Admin access) 1. Navigate to your EMM's Policy/App Configuration section and create a new policy targeted at Managed Devices/Android Enterprise. Select the Browser (Google Chrome) as the targeted application. Configure the URL Blocklist: Locate the URLBlocklist setting. Add the domains of the AI tools to be blocked. Examples of input include chatgpt.com, claude.ai, gemini.google.com, and v0.dev. Block Incognito Mode: 1. In the same Chrome configuration layout, look for IncognitoModeAvailability. 2. Set Incognito Mode to disabled. This ensures that users cannot bypass the URL block list by launching an anonymous browsing session. Assign and Push: Save the configuration and assign it to the device groups containing the user's COBO and COPE profiles. Configuration for other browsers depends on the deployment type. COBO: Because the first step limits the managed Google Play store to only approved apps, ensure no other browsers (like Firefox, Opera, or Edge) are approved in the app allow list. COPE: Create a Device Restrictions Policy for the Personal Profile and set "Disallow install of applications from unknown sources" to "True".