STIGQter STIGQter: STIG Summary:

Honeywell Android 13 COBO Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 22 Apr 2025

CheckedNameTitle
SV-274283r1100302_ruleHoneywell Android 13 must be configured to enforce a minimum password length of six characters.
SV-274284r1100305_ruleHoneywell Android 13 must be configured to not allow passwords that include more than four repeating or sequential characters.
SV-274285r1100308_ruleHoneywell Android 13 must be configured to lock the display after 15 minutes (or less) of inactivity.
SV-274286r1100311_ruleHoneywell Android 13 must be configured to not allow more than 10 consecutive failed authentication attempts.
SV-274287r1100314_ruleHoneywell Android 13 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store].
SV-274288r1100317_ruleHoneywell Android 13 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].
SV-274289r1100320_ruleHoneywell Android 13 allowlist must be configured to not include applications with the following characteristics: - Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DOD servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with user; - Payment processing; and - Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs, display screens (screen mirroring), or printers.
SV-274290r1100323_ruleHoneywell Android 13 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
SV-274294r1100335_ruleHoneywell Android 13 must be configured to disable trust agents.
SV-274296r1100341_ruleHoneywell Android 13 must be configured to disable developer modes.
SV-274299r1100350_ruleHoneywell Android 13 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device.
SV-274300r1100353_ruleHoneywell Android 13 must be configured to generate audit records for the following auditable events: Detected integrity violations.
SV-274304r1100365_ruleHoneywell Android 13 must be configured to disable USB mass storage mode.
SV-274305r1100368_ruleHoneywell Android 13 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.
SV-274306r1100371_ruleHoneywell Android 13 must be configured to not allow backup of [all applications, configuration data] to remote systems.
SV-274307r1100374_ruleHoneywell Android 13 must be configured to enable authentication of personal hotspot connections to the device using a preshared key.
SV-274309r1100447_ruleHoneywell Android 13 must be configured to disable multiuser modes.
SV-274313r1100392_ruleHoneywell Android 13 must be configured to disable Bluetooth or configured via User-Based Enforcement (UBE) to allow Bluetooth for only Headset Profile (HSP), Hands-Free Profile (HFP), and Serial Port Profile (SPP).
SV-274314r1100448_ruleHoneywell Android 13 must be configured to disable ad hoc wireless client-to-client connection capability.
SV-274315r1100449_ruleAll mobile Honeywell cryptography must be configured to be in FIPS 140-3 validated mode.
SV-274316r1100401_ruleHoneywell Android 13 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates.
SV-274317r1100404_ruleHoneywell Android 13 must be configured to enable audit logging.
SV-274318r1100455_ruleHoneywell Android 13 users must complete required training.
SV-274319r1100410_ruleHoneywell Android 13 must be configured to enforce that Wi-Fi Sharing is disabled.
SV-274320r1100413_ruleHoneywell Android 13 must have the DOD root and intermediate PKI certificates installed.
SV-274321r1100416_ruleThe Honeywell Android 13 work profile must be configured to prevent users from adding personal email accounts to the work email app.
SV-274322r1100419_ruleThe Honeywell Android 13 work profile must be configured to enforce the system application disable list.
SV-274323r1100422_ruleHoneywell Android 13 must be configured to disallow configuration of date and time.
SV-274325r1100428_ruleAndroid 13 devices must have the latest available Honeywell Android 13 operating system installed.
SV-274326r1100431_ruleAndroid 13 devices must be configured to disable the use of third-party keyboards.
SV-274327r1100446_ruleAndroid 13 devices must be configured to enable Common Criteria (CC) mode.
SV-274328r1100437_ruleHoneywell Android 13 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].