STIGQter STIGQter: STIG Summary: Honeywell Android 13 COPE Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Apr 2025:

Honeywell Android 13 must be configured to disable Bluetooth or configured via User-Based Enforcement (UBE) to allow Bluetooth for only Headset Profile (HSP), Hands-Free Profile (HFP), and Serial Port Profile (SPP).

DISA Rule

SV-274409r1100797_rule

Vulnerability Number

V-274409

Group Title

PP-MDF-333320

Rule Version

HONW-13-009400

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the Honeywell Android 13 device to disable Bluetooth, or if the AO has approved the use of Bluetooth (for example, for car hands-free use), train the user to connect to only authorized Bluetooth devices using only HSP, HFP, or SPP Bluetooth-capable devices (UBE).

To disable Bluetooth, use the following procedure:

On the EMM console:

COBO:

1. Open "User restrictions" section.
2. Toggle "Disallow Bluetooth" to "ON".

COPE:

1. Open "User restrictions on parent" section.
2. Toggle "Disallow Bluetooth" to "ON".

The user training requirement is satisfied in requirement HONW-13-009800.

Check Contents

Determine if the authorizing official (AO) has approved the use of Bluetooth at the site.

If the AO has not approved the use of Bluetooth, verify that Bluetooth has been disabled.

On the EMM console:

COBO:

1. Open "User restrictions" section.
2. Verify that "Disallow Bluetooth" is toggled to "ON".

COPE:

1. Open "User restrictions on parent" section.
2. Verify that "Disallow Bluetooth" is toggled to "ON".

On the managed Honeywell Android 13 device:

COBO and COPE:

1. Go to Settings >> Connected Devices >> Connection Preferences >> Bluetooth.
2. Verify that "Use Bluetooth" is set to "OFF" and cannot be toggled to "ON".

If the AO has approved the use of Bluetooth, on the managed Android 13 device:

1. Go to Settings >> Connected Devices.
2. Verify that only approved Bluetooth-connected devices using approved profiles are listed.

If the AO has not approved the use of Bluetooth, and Bluetooth use is not disabled via an EMM managed device policy, this is a finding.

If the AO has approved the use of Bluetooth, and Bluetooth devices using unauthorized Bluetooth profiles are listed on the device under "Connected devices", this is a finding.

Vulnerability Number

V-274409

Documentable

False

Rule Version

HONW-13-009400

Severity Override Guidance

Determine if the authorizing official (AO) has approved the use of Bluetooth at the site.

If the AO has not approved the use of Bluetooth, verify that Bluetooth has been disabled.

On the EMM console:

COBO:

1. Open "User restrictions" section.
2. Verify that "Disallow Bluetooth" is toggled to "ON".

COPE:

1. Open "User restrictions on parent" section.
2. Verify that "Disallow Bluetooth" is toggled to "ON".

On the managed Honeywell Android 13 device:

COBO and COPE:

1. Go to Settings >> Connected Devices >> Connection Preferences >> Bluetooth.
2. Verify that "Use Bluetooth" is set to "OFF" and cannot be toggled to "ON".

If the AO has approved the use of Bluetooth, on the managed Android 13 device:

1. Go to Settings >> Connected Devices.
2. Verify that only approved Bluetooth-connected devices using approved profiles are listed.

If the AO has not approved the use of Bluetooth, and Bluetooth use is not disabled via an EMM managed device policy, this is a finding.

If the AO has approved the use of Bluetooth, and Bluetooth devices using unauthorized Bluetooth profiles are listed on the device under "Connected devices", this is a finding.

Check Content Reference

M

Target Key

5702