| Checked | Name | Title |
|---|
| ☐ | SV-276748r1140036_rule | Google Android 16 must be configured to enable audit logging. |
| ☐ | SV-276749r1140039_rule | Google Android 16 must be configured to enforce a minimum password length of six characters. |
| ☐ | SV-276750r1140042_rule | Google Android 16 must be configured to not allow passwords that include more than four repeating or sequential characters. |
| ☐ | SV-276751r1140045_rule | Google Android 16 must be configured to lock the display after 15 minutes (or less) of inactivity. |
| ☐ | SV-276752r1140048_rule | Google Android 16 must be configured to not allow more than 10 consecutive failed authentication attempts. |
| ☐ | SV-276753r1140051_rule | Google Android 16 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store]. |
| ☐ | SV-276754r1140054_rule | Google Android 16 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version]. |
| ☐ | SV-276755r1140057_rule | Google Android 16 allowlist must be configured to not include applications with the following characteristics:
- Backs up mobile device (MD) data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Voice assistant application if available when MD is locked;
- Voice dialing application if available when MD is locked;
- Allows synchronization of data or applications between devices associated with user;
- Payment processing;
- Allows unencrypted (or encrypted but not FIPS 140-2/140-3 validated) data sharing with other MDs or printers;
- Backs up own data to a remote system;
- Renders TV shows and movies. |
| ☐ | SV-276756r1140662_rule | Google Android 16 allowlist must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini. |
| ☐ | SV-276757r1140063_rule | Google Android 16 must be configured to not display the following (work profile) notifications when the device is locked: [selection:
a. email notifications
b. calendar appointments
c. contact associated with phone call notification
d. text message notification
e. other application-based notifications
f. all notifications]. |
| ☐ | SV-276758r1140066_rule | Google Android 16 must be configured to disable trust agents. |
| ☐ | SV-276759r1140069_rule | Google Android 16 must be configured to disable developer modes. |
| ☐ | SV-276760r1140072_rule | Google Android 16 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. |
| ☐ | SV-276761r1140075_rule | Google Android 16 must be configured to generate audit records for the following auditable events: Detected integrity violations. |
| ☐ | SV-276762r1140078_rule | Google Android 16 must be configured to disable USB mass storage mode. |
| ☐ | SV-276763r1140081_rule | Google Android 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems. |
| ☐ | SV-276764r1140084_rule | Google Android 16 must be configured to not allow backup of [all applications, configuration data] to remote systems. |
| ☐ | SV-276765r1140087_rule | Google Android 16 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. |
| ☐ | SV-276766r1140090_rule | Google Android 16 must be configured to disable multiuser modes. |
| ☐ | SV-276767r1140665_rule | Google Android 16 must be configured to disable Bluetooth or configured via User Based Enforcement (UBE) to allow Bluetooth for only Headset Profile (HSP), Hands-Free Profile (HFP), and Serial Port Profile (SPP). |
| ☐ | SV-276768r1140096_rule | Google Android 16 must be configured to disable ad hoc wireless client-to-client connection capability. |
| ☐ | SV-276769r1140099_rule | Google Android 16 users must complete required training. |
| ☐ | SV-276770r1140102_rule | Google Android 16 must be configured to disable Wi-Fi Sharing. |
| ☐ | SV-276771r1140105_rule | Google Android 16 must be configured to enforce a password for Wi-Fi and Bluetooth hotspot if approved for use by the authorizing official (AO). If not approved for use, Wi-Fi and Bluetooth hotspot must be disabled. |
| ☐ | SV-276772r1140108_rule | Google Android 16 must have the DOD root and intermediate PKI certificates installed. |
| ☐ | SV-276773r1140111_rule | The Google Android 16 work profile must be configured to enforce the system application disable list. |
| ☐ | SV-276774r1140114_rule | The Google Android 16 work profile must be configured to disable automatic completion of workspace internet browser text input. |
| ☐ | SV-276775r1140673_rule | The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps. |
| ☐ | SV-276777r1140123_rule | Android 16 devices must have the latest available Google Android 16 operating system installed. |
| ☐ | SV-276778r1140126_rule | Android 16 devices must be configured to disable the use of third-party keyboards. |
| ☐ | SV-276779r1140129_rule | Android 16 devices must be configured to enable Common Criteria (CC) Mode. |
| ☐ | SV-276780r1140132_rule | Google Android 16 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)]. |
| ☐ | SV-276781r1140135_rule | Google Android 16 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates. |
| ☐ | SV-276782r1140138_rule | Google Android 16 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub. |
| ☐ | SV-276783r1140141_rule | Google Android 16 must be configured to disable "Private Space" use. |
| ☐ | SV-276784r1183777_rule | Google Android 16 must disable the user's ability to wipe the device. |
| ☐ | SV-276786r1140150_rule | Google Android 16 must disable wireless printing. |
| ☐ | SV-276787r1140153_rule | Google Android 16 must disable screen capture. |
| ☐ | SV-276788r1140156_rule | Google Android 16 devices must have a Mobile Threat Detection (MTD) app installed. |
| ☐ | SV-276789r1140159_rule | Google Android 16 must implement the management setting: disable Camera. |