| Checked | Name | Title |
|---|
| ☐ | SV-276536r1139783_rule | Samsung Android must be configured to disable all Bluetooth profiles except for Headset Profile (HSP), Hands-Free Profile (HFP), Serial Port Profile (SPP), Advanced Audio Distribution Profile (A2DP), Audio/Video Remote Control Profile (AVRCP), and Phone Book Access Profile (PBAP). |
| ☐ | SV-276537r1139133_rule | Samsung Android's Work profile must allow only the Administrator (management tool) to perform the following management function: Install/remove DOD root and intermediate PKI certificates. |
| ☐ | SV-276538r1139136_rule | Samsung Android must be configured to disallow configuration of the device's date and time. |
| ☐ | SV-276539r1139139_rule | Samsung Android must be configured to enable authentication of personal hotspot connections to the device using a preshared key. |
| ☐ | SV-276540r1139142_rule | Samsung Android must be configured to disable developer modes. |
| ☐ | SV-276541r1183721_rule | Samsung Android 16 must disable the ability of the user to wipe the device. |
| ☐ | SV-276542r1139148_rule | Samsung Android must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including DOD-approved commercial app repository, management tool server, or mobile application store. |
| ☐ | SV-276543r1139151_rule | Samsung Android must be configured to not allow backup of all applications and configuration data to remote systems. (This requirement applies to the Work Profile for COPE.)
- Disable Data Sync Framework. |
| ☐ | SV-276544r1139154_rule | Samsung Android's Work profile must be configured to prevent users from adding personal email accounts to the work email app. |
| ☐ | SV-276545r1139157_rule | Samsung Android must be configured to enable encryption for data at rest on removable storage media or, alternately, the use of removable storage media must be disabled. |
| ☐ | SV-276546r1139160_rule | Samsung Android 16 must disable wireless printing. |
| ☐ | SV-276547r1139163_rule | Samsung Android must be configured to disable USB mass storage mode. |
| ☐ | SV-276548r1139166_rule | Samsung Android must be configured to not allow backup of all applications and configuration data to locally connected systems. |
| ☐ | SV-276549r1139169_rule | Samsung Android must be configured to disable ad hoc wireless client-to-client connection capability. |
| ☐ | SV-276550r1140696_rule | The Samsung Android device must be configured to enforce that Wi-Fi Sharing is disabled. |
| ☐ | SV-276551r1139175_rule | Samsung Android's Work profile must have the DOD root and intermediate PKI certificates installed. |
| ☐ | SV-276552r1139178_rule | The Samsung Android device work profile must be configured to enforce the system application disable list. |
| ☐ | SV-276553r1139181_rule | Samsung Android must not accept the certificate when it cannot establish a connection to determine the validity of a certificate. |
| ☐ | SV-276554r1139184_rule | Samsung Android's Work profile must be configured to enable Common Criteria (CC) mode. |
| ☐ | SV-276555r1139187_rule | Samsung Android must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. |
| ☐ | SV-276556r1139190_rule | Samsung Android must be configured to disable authentication mechanisms providing user access to protected data other than a Password Authentication Factor: Face recognition. |
| ☐ | SV-276557r1139193_rule | Samsung Android must be configured to enable a screen-lock policy that will lock the display after a period of inactivity - Disable trust agents. |
| ☐ | SV-276558r1139196_rule | Samsung Android must be configured to not display the following (Work Environment) notifications when the device is locked: All notifications. |
| ☐ | SV-276559r1139199_rule | Samsung Android must be configured to not allow more than 10 consecutive failed authentication attempts. |
| ☐ | SV-276560r1139202_rule | Samsung Android must be configured to lock the display after 15 minutes (or less) of inactivity. |
| ☐ | SV-276561r1139205_rule | The Samsung Android device must be configured to perform the following management function: Disable Phone Hub. |
| ☐ | SV-276562r1139208_rule | Samsung Android must be configured to enforce a minimum password length of six characters. |
| ☐ | SV-276563r1139211_rule | Samsung Android must be configured to not allow passwords that include more than four repeating or sequential characters. |
| ☐ | SV-276564r1139214_rule | The Samsung Android device must be configured to disable the use of third-party keyboards. |
| ☐ | SV-276565r1139769_rule | Samsung Android 16 must disable screen capture. |
| ☐ | SV-276566r1139220_rule | Samsung Android's Work profile must be configured to enable audit logging. |
| ☐ | SV-276567r1139223_rule | The Samsung Android device must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)]. |
| ☐ | SV-276568r1139226_rule | The Samsung Android device must be configured to enable Certificate Revocation List (CRL) status checking. |
| ☐ | SV-276569r1139229_rule | Samsung Android allowlist must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini. |
| ☐ | SV-276614r1139364_rule | Samsung Android's Work profile must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: Names. |
| ☐ | SV-276615r1139367_rule | Samsung Android's Work profile must be configured to not allow installation of applications with the following characteristics:
- Back up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmit MD diagnostic data to non-DOD servers;
- Voice assistant application if available when MD is locked;
- Voice dialing application if available when MD is locked;
- Allows synchronization of data or applications between devices associated with user; and
- Allows unencrypted (or encrypted but not FIPS 140-2/140-3-validated) data sharing with other MDs or printers.
- Apps that backup their own data to a remote system.
- Apps that render TV shows and movies. |
| ☐ | SV-276625r1139397_rule | Samsung Android must be configured to not allow backup of all applications and configuration data to remote systems.
- Disable Backup Services. |
| ☐ | SV-276632r1139418_rule | Samsung Android must be enrolled as a COBO device. |
| ☐ | SV-276633r1139765_rule | Samsung Android device users must complete required training. |
| ☐ | SV-276634r1140692_rule | The Samsung Android device must have the latest available Samsung Android operating system (OS) installed. |
| ☐ | SV-276635r1139770_rule | Samsung Android 16 devices must have a Mobile Threat Detection (MTD) app installed. |
| ☐ | SV-276636r1139772_rule | Samsung Android 16 must implement the management setting: disable Camera. |
| ☐ | SV-279245r1140702_rule | The Samsung Android device must be configured to disable Wi-Fi Aware for Work Profile apps. |