STIGQter STIGQter: STIG Summary: Samsung Android 16 COPE Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 13 May 2026:

Samsung Android's Work profile must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: Names.

DISA Rule

SV-276722r1139688_rule

Vulnerability Number

V-276722

Group Title

PP-MDF-333060

Rule Version

KNOX-16-005500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

COPE:
Configure the Work profile on Samsung Android devices to allow users to install only applications that have been approved by the AO.

COBO:
Configure Samsung Android devices to allow users to install only applications that have been approved by the AO.

In addition to any local policy, the AO must not approve applications that have certain prohibited characteristics; these are covered in KNOX-16-005600.

On the management tool, in the app catalog for managed Google Play, add each AO-approved app to be available.

Note: Managed Google Play is an allowed App Store.

Check Contents

COPE:
Review the configuration to determine if the Work profile on the Samsung Android device is allowing users to install only applications that have been approved by the authorizing official (AO).

COBO:
Review the configuration to determine if the Samsung Android devices are allowing users to install only applications that have been approved by the AO.

This validation procedure is performed only on the management tool.

On the management tool, in the app catalog for managed Google Play, verify that only AO-approved apps are available.

If on the management tool the app catalog for managed Google Play includes non-AO-approved apps, this is a finding.

Vulnerability Number

V-276722

Documentable

False

Rule Version

KNOX-16-005500

Severity Override Guidance

COPE:
Review the configuration to determine if the Work profile on the Samsung Android device is allowing users to install only applications that have been approved by the authorizing official (AO).

COBO:
Review the configuration to determine if the Samsung Android devices are allowing users to install only applications that have been approved by the AO.

This validation procedure is performed only on the management tool.

On the management tool, in the app catalog for managed Google Play, verify that only AO-approved apps are available.

If on the management tool the app catalog for managed Google Play includes non-AO-approved apps, this is a finding.

Check Content Reference

M

Target Key

5715