STIGQter STIGQter: STIG Summary: Samsung Android 16 COBO Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 13 May 2026:

Samsung Android's Work profile must have the DOD root and intermediate PKI certificates installed.

DISA Rule

SV-276551r1139175_rule

Vulnerability Number

V-276551

Group Title

PP-MDF-993300

Rule Version

KNOX-16-009000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install the DOD root and intermediate PKI certificates into the Samsung Android devices (install in Work profile for COPE).

The current DOD root and intermediate PKI certificates may be obtained in self-extracting zip files at https://cyber.mil/pki-pke (for NIPRNet).

On the management tool, in the device policy management (Work profile for COPE), install the DOD root and intermediate PKI certificates.

API: installCaCert

Check Contents

COPE:
Review the configuration to determine if the Samsung Android's Work profile has the DOD root and intermediate PKI certificates installed.

This validation procedure is performed on both the management tool and the Samsung Android device.

The current DOD root and intermediate PKI certificates may be obtained in self-extracting zip files at https://cyber.mil/pki-pke (for NIPRNet).

On the management tool, in the Work profile policy management, verify the DOD root and intermediate PKI certificates are installed.

On the Samsung Android device:
1. Open Settings >> Security and privacy >> More security settings >> View security certificates.
2. In the User tab, verify the DOD root and intermediate PKI certificates are listed in the Work profile.

If on the management tool the DOD root and intermediate PKI certificates are not listed in the Work profile, or on the Samsung Android device the DOD root and intermediate PKI certificates are not listed in the Work profile, this is a finding.

COBO:
Review the configuration to determine if the Samsung Android devices have the DOD root and intermediate PKI certificates installed.

This validation procedure is performed on both the management tool and the Samsung Android device.

The current DOD root and intermediate PKI certificates may be obtained in self-extracting zip files at https://cyber.mil/pki-pke (for NIPRNet).

On the management tool, in the device policy management, verify the DOD root and intermediate PKI certificates are installed.

On the Samsung Android device:
1. Open Settings >> Security and privacy >> More security settings >> View security certificates.
2. In the User tab, verify the DOD root and intermediate PKI certificates are listed in the device.

If on the management tool the DOD root and intermediate PKI certificates are not listed in the device, or on the Samsung Android device the DOD root and intermediate PKI certificates are not listed in the device, this is a finding.

Vulnerability Number

V-276551

Documentable

False

Rule Version

KNOX-16-009000

Severity Override Guidance

COPE:
Review the configuration to determine if the Samsung Android's Work profile has the DOD root and intermediate PKI certificates installed.

This validation procedure is performed on both the management tool and the Samsung Android device.

The current DOD root and intermediate PKI certificates may be obtained in self-extracting zip files at https://cyber.mil/pki-pke (for NIPRNet).

On the management tool, in the Work profile policy management, verify the DOD root and intermediate PKI certificates are installed.

On the Samsung Android device:
1. Open Settings >> Security and privacy >> More security settings >> View security certificates.
2. In the User tab, verify the DOD root and intermediate PKI certificates are listed in the Work profile.

If on the management tool the DOD root and intermediate PKI certificates are not listed in the Work profile, or on the Samsung Android device the DOD root and intermediate PKI certificates are not listed in the Work profile, this is a finding.

COBO:
Review the configuration to determine if the Samsung Android devices have the DOD root and intermediate PKI certificates installed.

This validation procedure is performed on both the management tool and the Samsung Android device.

The current DOD root and intermediate PKI certificates may be obtained in self-extracting zip files at https://cyber.mil/pki-pke (for NIPRNet).

On the management tool, in the device policy management, verify the DOD root and intermediate PKI certificates are installed.

On the Samsung Android device:
1. Open Settings >> Security and privacy >> More security settings >> View security certificates.
2. In the User tab, verify the DOD root and intermediate PKI certificates are listed in the device.

If on the management tool the DOD root and intermediate PKI certificates are not listed in the device, or on the Samsung Android device the DOD root and intermediate PKI certificates are not listed in the device, this is a finding.

Check Content Reference

M

Target Key

5714