STIGQter STIGQter: STIG Summary: Samsung Android 16 COPE Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 13 May 2026:

Samsung Android's Work profile must be configured to not allow installation of applications with the following characteristics: - Back up MD data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmit MD diagnostic data to non-DOD servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with user; and - Allows unencrypted (or encrypted but not FIPS 140-2/140-3-validated) data sharing with other MDs or printers. - Apps that backup their own data to a remote system. - Apps that render TV shows and movies.

DISA Rule

SV-276723r1139691_rule

Vulnerability Number

V-276723

Group Title

PP-MDF-333070

Rule Version

KNOX-16-005600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The authorizing official (AO) must not approve applications with the following characteristics for installation by users in the Work profile:

- Back up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmit MD diagnostic data to non-DOD servers;
- Voice assistant application if available when MD is locked;
- Voice dialing application if available when MD is locked;
- Allows synchronization of data or applications between devices associated with user;
- Payment processing; and
- Allows unencrypted (or encrypted but not FIPS 140-2/140-3-validated) data sharing with other MDs, display screens (screen mirroring), or printers.
- Apps that backup their own data to a remote system.
- Apps that render TV shows and movies.

Implement managed Google Play (refer to requirement KNOX-16-005500).

Check Contents

Verify requirement KNOX-16-005500 (managed Google Play) has been implemented. Verify no apps with unapproved apps are listed in approved apps.

If managed Google Play has not been implemented or unapproved apps are allowed, this is a finding.

Vulnerability Number

V-276723

Documentable

False

Rule Version

KNOX-16-005600

Severity Override Guidance

Verify requirement KNOX-16-005500 (managed Google Play) has been implemented. Verify no apps with unapproved apps are listed in approved apps.

If managed Google Play has not been implemented or unapproved apps are allowed, this is a finding.

Check Content Reference

M

Target Key

5715