STIGQter STIGQter: STIG Summary: Samsung Android 16 COPE Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 13 May 2026:

Samsung Android's Work profile must be configured to disable exceptions to the access control policy that prevent application processes and groups of application processes from accessing all data stored by other application processes and groups of application processes.

DISA Rule

SV-276646r1139460_rule

Vulnerability Number

V-276646

Group Title

PP-MDF-333280

Rule Version

KNOX-16-007900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Samsung Android devices to enable an access control policy that prevents application processes and groups of application processes from accessing all data stored by other application processes and groups of application processes.

On the management tool, in the Work profile restrictions section, set "Cross profile copy/paste" to "Disallow".

API: addUserRestriction, DISALLOW_CROSS_PROFILE_COPY_PASTE

Check Contents

Review the Samsung documentation and inspect the configuration to verify the Samsung Android devices are enabling an access control policy that prevents application processes and groups of application processes from accessing all data stored by other application processes and groups of application processes.

This validation procedure is performed on both the management tool and the Samsung Android device.

On the management tool, in the Work profile restrictions, set "Cross profile copy/paste" to "Disallow".

On the Samsung Android device:
1. Using any Work app, copy text to the clipboard.
2. Using any Personal app, verify the clipboard text cannot be pasted.

If on the management tool "Cross profile copy/paste" is not set to "Disallow", or on the Samsung Android device the clipboard text can be pasted into a Personal app, this is a finding.

Vulnerability Number

V-276646

Documentable

False

Rule Version

KNOX-16-007900

Severity Override Guidance

Review the Samsung documentation and inspect the configuration to verify the Samsung Android devices are enabling an access control policy that prevents application processes and groups of application processes from accessing all data stored by other application processes and groups of application processes.

This validation procedure is performed on both the management tool and the Samsung Android device.

On the management tool, in the Work profile restrictions, set "Cross profile copy/paste" to "Disallow".

On the Samsung Android device:
1. Using any Work app, copy text to the clipboard.
2. Using any Personal app, verify the clipboard text cannot be pasted.

If on the management tool "Cross profile copy/paste" is not set to "Disallow", or on the Samsung Android device the clipboard text can be pasted into a Personal app, this is a finding.

Check Content Reference

M

Target Key

5715