STIGQter STIGQter: STIG Summary: Google Android 10.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

Google Android 10 must be configured to not allow backup of all applications and configuration data to remote systems.

DISA Rule

SV-108055r1_rule

Vulnerability Number

V-98951

Group Title

PP-MDF-301230

Rule Version

GOOG-10-003900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Google Android device to disable backup to remote systems (including commercial clouds).

NOTE: On a Restrictions, data in the work profile cannot be backed up by default.

On the MDM console:

1. Open User restrictions.
2. Ensure "Enable backup service" is not selected.

Check Contents

Review Google Android device configuration settings to determine if the capability to back up to a remote system has been disabled.

This validation procedure is performed on both the MDM Administration Console and the Android 10 device.

On the MDM console, do the following:

1. Open User restrictions.
2. Ensure "Disallow backup servicer" is not selected.

On the Android 10 device, do the following:

1. Go to Settings >> System.
2. Ensure Backup is set to "Off".

If the MDM console device policy is not set to disable the capability to back up to a remote system or on the Android 10 device, the device policy is not set to disable the capability to back up to a remote system, this is a finding.

Vulnerability Number

V-98951

Documentable

False

Rule Version

GOOG-10-003900

Severity Override Guidance

Review Google Android device configuration settings to determine if the capability to back up to a remote system has been disabled.

This validation procedure is performed on both the MDM Administration Console and the Android 10 device.

On the MDM console, do the following:

1. Open User restrictions.
2. Ensure "Disallow backup servicer" is not selected.

On the Android 10 device, do the following:

1. Go to Settings >> System.
2. Ensure Backup is set to "Off".

If the MDM console device policy is not set to disable the capability to back up to a remote system or on the Android 10 device, the device policy is not set to disable the capability to back up to a remote system, this is a finding.

Check Content Reference

M

Target Key

3581

Comments