STIGQter STIGQter: STIG Summary: Honeywell Android 13 COBO Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Apr 2025:

All mobile Honeywell cryptography must be configured to be in FIPS 140-3 validated mode.

DISA Rule

SV-274315r1100449_rule

Vulnerability Number

V-274315

Group Title

PP-MDF-333340

Rule Version

HONW-13-009600

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

On the MDM console (for SDM660 only):

1. Ask the MDM administrator to edit the following item in DeviceConfig.xml:
Modify item: DeviceConfig >> HoneywellSetting >> EnforceOSFipsMode.
Value sample: 1: Enable OS FIPS mode; 0: Disable OS FIPS mode.
2. In the MDM console, the MDM administrator will package this DeviceConfig.xml and push this package to the CN80G device.

On the Honeywell Android 13 device (SDM660 only):

1. Open Settings >> Honeywell Settings >> FIPS Enforce Mode.
2. Enable "FIPS Enforce Mode".

Check Contents

Review the configuration to determine if the Honeywell Android devices are in FIPS mode.

On the MDM console (for SDM660 only):

1. In the MDM console, load the active DeviceConfig.xml for the managed device.
2. Verify that item DeviceConfig >> HoneywellSetting >> EnforceOSFipsMode has a value of "1" for "Enable OS FIPS Mode".

On the Honeywell Android 13 device (SDM660 only):

1. Open Settings >> Honeywell Settings >> FIPS Enforce Mode.
2. Verify that "FIPS Enforce Mode" is enabled.

If "FIPS Enforce Mode" is not enabled, this is a finding.

Vulnerability Number

V-274315

Documentable

False

Rule Version

HONW-13-009600

Severity Override Guidance

Review the configuration to determine if the Honeywell Android devices are in FIPS mode.

On the MDM console (for SDM660 only):

1. In the MDM console, load the active DeviceConfig.xml for the managed device.
2. Verify that item DeviceConfig >> HoneywellSetting >> EnforceOSFipsMode has a value of "1" for "Enable OS FIPS Mode".

On the Honeywell Android 13 device (SDM660 only):

1. Open Settings >> Honeywell Settings >> FIPS Enforce Mode.
2. Verify that "FIPS Enforce Mode" is enabled.

If "FIPS Enforce Mode" is not enabled, this is a finding.

Check Content Reference

M

Target Key

5701