STIGQter STIGQter: STIG Summary: Honeywell Android 13 COPE Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Apr 2025:

Honeywell Android 13 must be configured to disable exceptions to the access control policy that prevent [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].

DISA Rule

SV-274404r1100782_rule

Vulnerability Number

V-274404

Group Title

PP-MDF-333280

Rule Version

HONW-13-008900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Honeywell Android 13 device to enable the access control policy that prevents [selection: application processes, groups of application processes]  from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].

Note: All application data is inherently sandboxed and isolated from other applications. To disable copy/paste on the EMM console:

COPE:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Toggle "Disallow cross profile copy/paste" to "ON".
4. Toggle "Disallow sharing data into the profile" to "ON".

Check Contents

Review documentation on the managed Honeywell Android 13 device and inspect the configuration on the Honeywell Android device to verify that the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.

This validation procedure is performed only on the EMM Administration Console.

On the EMM console:

COPE:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow cross profile copy/paste" is toggled to "ON".
4. Verify that "Disallow sharing data into the profile" is toggled to "ON".

If the EMM console device policy is not set to disable data sharing between profiles, this is a finding.

Vulnerability Number

V-274404

Documentable

False

Rule Version

HONW-13-008900

Severity Override Guidance

Review documentation on the managed Honeywell Android 13 device and inspect the configuration on the Honeywell Android device to verify that the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.

This validation procedure is performed only on the EMM Administration Console.

On the EMM console:

COPE:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow cross profile copy/paste" is toggled to "ON".
4. Verify that "Disallow sharing data into the profile" is toggled to "ON".

If the EMM console device policy is not set to disable data sharing between profiles, this is a finding.

Check Content Reference

M

Target Key

5702