STIGQter STIGQter: STIG Summary: Google Android 15 COPE Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 13 May 2026:

Google Android 15 must be configured to enforce a password for Wi-Fi and Bluetooth hotspot, if approved for use by the authorizing official (AO). If not approved for use, Wi-Fi and Bluetooth hotspot must be disabled.

DISA Rule

SV-267549r1031832_rule

Vulnerability Number

V-267549

Group Title

PP-MDF-993300

Rule Version

GOOG-15-009950

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable hotspot functions on the DOD phone if not approved by the AO.

On the EMM console:

COBO:

1. Open "Set user restrictions".
2. Toggle "Disallow config tethering" to "ON".

COPE:

1. Open "Set user restrictions on parent".
2. Toggle "Disallow config tethering" to "ON".

If the use of Wi-Fi and Bluetooth hotspots has been approved by the AO, train the user to not change the default hotspot password (see GOOG-15-009800). By default, when Wi-Fi Hotspot is enabled, a 15-character complex password is automatically configured for the hotspot.

Check Contents

Review device configuration, user training, and determine if the AO has approved hotspot use.

If the AO has not approved hotspot use, verify hotspot use has been disabled:

On the EMM console:

COBO:

1. Open "Set user restrictions".
2. Verify "Disallow config tethering" is toggled to "ON".

COPE:

1. Open "Set user restrictions on parent".
2. Toggle "Disallow config tethering" to "ON".

On the managed Google Android 15 device:

COBO and COPE:

1. Go to Settings >> Network & Internet.
2. Verify "Hotspot & tethering" is "Controlled by admin".
3. Verify that tapping "Hotspot & tethering" provides a prompt to the user specifying "Action not allowed".

If on the managed Google Android 15 device "Hotspot & tethering" is enabled, this is a finding.

If hotspot use has been approved, verify the user has been trained to use the default hotspot password. See GOOG-15-009800 for procedure.

If users are not trained to use the default hotspot password, this is a finding.

Vulnerability Number

V-267549

Documentable

False

Rule Version

GOOG-15-009950

Severity Override Guidance

Review device configuration, user training, and determine if the AO has approved hotspot use.

If the AO has not approved hotspot use, verify hotspot use has been disabled:

On the EMM console:

COBO:

1. Open "Set user restrictions".
2. Verify "Disallow config tethering" is toggled to "ON".

COPE:

1. Open "Set user restrictions on parent".
2. Toggle "Disallow config tethering" to "ON".

On the managed Google Android 15 device:

COBO and COPE:

1. Go to Settings >> Network & Internet.
2. Verify "Hotspot & tethering" is "Controlled by admin".
3. Verify that tapping "Hotspot & tethering" provides a prompt to the user specifying "Action not allowed".

If on the managed Google Android 15 device "Hotspot & tethering" is enabled, this is a finding.

If hotspot use has been approved, verify the user has been trained to use the default hotspot password. See GOOG-15-009800 for procedure.

If users are not trained to use the default hotspot password, this is a finding.

Check Content Reference

M

Target Key

5654