STIGQter STIGQter: STIG Summary: Honeywell Android 9.x COBO Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 14 Jan 2021:

The Honeywell Mobility Edge Android Pie device must be configured to display the DoD advisory warning message at start-up or each time the user unlocks the device.

DISA Rule

SV-235046r626530_rule

Vulnerability Number

V-235046

Group Title

PP-MDF-301200

Rule Version

HONW-09-003400

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the DoD warning banner by either of the following methods (required text is found in the Vulnerability Description):
1. By placing the DoD warning banner text in the user agreement signed by each Honeywell Android device user (preferred method).
2. By configuring the warning banner text on the MDM console and installing the banner on each managed mobile device.

On the MDM console:
Enable "Lock Screen Message" and enter the banner text.

Check Contents

The DoD warning banner can be displayed by either of the following methods (required text is found in the Vulnerability Description):

1. By placing the DoD warning banner text in the user agreement signed by each Honeywell Android device user (preferred method).
2. By configuring the warning banner text on the MDM console and installing the banner on each managed mobile device.

Determine which method is used at the Honeywell Android device site and follow the appropriate validation procedure below.

Validation Procedure for Method #1:
Review the signed user agreements for several Honeywell Android device users and verify the agreement includes the required DoD warning banner text.

Validation Procedure for Method #2:
On the MDM console:
Ensure "Lock Screen Message" and the appropriate banner text is included.

If, for Method #1, the required warning banner text is not on all signed user agreements reviewed, or for Method #2, the MDM console device policy is not set to display a warning banner with the appropriate designated wording or on the Honeywell Android Pie device, the device policy is not set to display a warning banner with the appropriate designated wording, this is a finding.

Vulnerability Number

V-235046

Documentable

False

Rule Version

HONW-09-003400

Severity Override Guidance

The DoD warning banner can be displayed by either of the following methods (required text is found in the Vulnerability Description):

1. By placing the DoD warning banner text in the user agreement signed by each Honeywell Android device user (preferred method).
2. By configuring the warning banner text on the MDM console and installing the banner on each managed mobile device.

Determine which method is used at the Honeywell Android device site and follow the appropriate validation procedure below.

Validation Procedure for Method #1:
Review the signed user agreements for several Honeywell Android device users and verify the agreement includes the required DoD warning banner text.

Validation Procedure for Method #2:
On the MDM console:
Ensure "Lock Screen Message" and the appropriate banner text is included.

If, for Method #1, the required warning banner text is not on all signed user agreements reviewed, or for Method #2, the MDM console device policy is not set to display a warning banner with the appropriate designated wording or on the Honeywell Android Pie device, the device policy is not set to display a warning banner with the appropriate designated wording, this is a finding.

Check Content Reference

M

Target Key

5275

Comments