STIGQter STIGQter: STIG Summary: Google Android 14 BYOAD Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 13 Mar 2024:

The EMM system supporting the Google Android 14 BYOAD must be NIAP validated (included on the NIAP list of compliant products or products in evaluation) unless the DOD CIO has granted an Approved Exception to Policy (E2P).

DISA Rule

SV-260070r948415_rule

Vulnerability Number

V-260070

Group Title

PP-BYO-000200

Rule Version

GOOG-14-802000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Only use an EMM system supporting the Google Android 14 BYOAD that is NIAP validated (included on the NIAP list of compliant products or products in evaluation), unless the DOD CIO has granted an Approved Exception to Policy (E2P).

Note: For a VMI solution, both the client and server components must be NIAP compliant.

Check Contents

Verify the EMM system supporting the Google Android 14 BYOAD is NIAP-validated (included on the NIAP list of compliant products or products in evaluation). If not, verify the DOD CIO has granted an Approved Exception to Policy (E2P).

Note: For a VMI solution, both the client and server components must be NIAP compliant.

If the EMM system supporting the Google Android 14 BYOAD is not NIAP-validated (included on the NIAP list of compliant products or products in evaluation) and the DOD CIO has not granted an Approved Exception to Policy (E2P), this is a finding.

Vulnerability Number

V-260070

Documentable

False

Rule Version

GOOG-14-802000

Severity Override Guidance

Verify the EMM system supporting the Google Android 14 BYOAD is NIAP-validated (included on the NIAP list of compliant products or products in evaluation). If not, verify the DOD CIO has granted an Approved Exception to Policy (E2P).

Note: For a VMI solution, both the client and server components must be NIAP compliant.

If the EMM system supporting the Google Android 14 BYOAD is not NIAP-validated (included on the NIAP list of compliant products or products in evaluation) and the DOD CIO has not granted an Approved Exception to Policy (E2P), this is a finding.

Check Content Reference

M

Target Key

5588