STIGQter STIGQter: STIG Summary: Samsung Android OS 7 with Knox 2.x Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 25 Oct 2019: The Samsung Android 7 with Knox must implement the management setting: Configure application install blacklist.

DISA Rule

SV-91273r1_rule

Vulnerability Number

V-76577

Group Title

PP-MDF-991000

Rule Version

KNOX-07-012500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Samsung Android 7 with Knox to Blacklist Application Install.

On the MDM console, do one of the following:
1. Add all package names by wildcard ('.*') to the "Package Name Blacklist" setting in the "Android Applications" rule.
2. Add all digital signatures by wildcard ('.*') to the "Signature Blacklist" setting in the "Android Applications" rule.

Check Contents

Note, this requirement is Not Applicable if the AO has approved unmanaged personal space/container (COPE use case). The site must have an AO signed document showing the AO has assumed the risk for using an unmanaged personal container.

Review Samsung Android 7 with Knox configuration settings to determine if the mobile device is Blacklisting Application Install.

This validation procedure is performed on the MDM Administration Console only.

On the MDM console, do 1 & 2 or 3 & 4:
1. Ask the MDM administrator to display the "Package Name Blacklist" setting in the "Android Applications" rule.
2. Verify the setting is configured to include all package names (specified by the wildcard string ".*").
OR
3. Ask the MDM administrator to display the "Signature Blacklist" setting in the "Android Applications" rule.
4. Verify the setting is configured to include all digital signatures (specified by the wildcard string ".*").

If the MDM console "Package Name Blacklist" or "Signature Blacklist" settings are not set to include all entries, this is a finding.

Vulnerability Number

V-76577

Documentable

False

Rule Version

KNOX-07-012500

Severity Override Guidance

Note, this requirement is Not Applicable if the AO has approved unmanaged personal space/container (COPE use case). The site must have an AO signed document showing the AO has assumed the risk for using an unmanaged personal container.

Review Samsung Android 7 with Knox configuration settings to determine if the mobile device is Blacklisting Application Install.

This validation procedure is performed on the MDM Administration Console only.

On the MDM console, do 1 & 2 or 3 & 4:
1. Ask the MDM administrator to display the "Package Name Blacklist" setting in the "Android Applications" rule.
2. Verify the setting is configured to include all package names (specified by the wildcard string ".*").
OR
3. Ask the MDM administrator to display the "Signature Blacklist" setting in the "Android Applications" rule.
4. Verify the setting is configured to include all digital signatures (specified by the wildcard string ".*").

If the MDM console "Package Name Blacklist" or "Signature Blacklist" settings are not set to include all entries, this is a finding.

Check Content Reference

M

Target Key

3253

Comments