STIGQter STIGQter: STIG Summary:

Samsung Android 16 COPE Security Technical Implementation Guide

Version: 1

Release: 3 Benchmark Date: 13 May 2026

CheckedNameTitle
SV-276641r1139445_ruleThe Samsung Android device work profile must be configured to disable the autofill services.
SV-276642r1139785_ruleSamsung Android must be configured to disable all Bluetooth profiles except for Headset Profile (HSP), Hands-Free Profile (HFP), Serial Port Profile (SPP), Advanced Audio Distribution Profile (A2DP), Audio/Video Remote Control Profile (AVRCP), and Phone Book Access Profile (PBAP).
SV-276643r1139451_ruleSamsung Android's Work profile must allow only the Administrator (management tool) to perform the following management function: Install/remove DOD root and intermediate PKI certificates.
SV-276644r1139454_ruleSamsung Android must be configured to disallow configuration of the device's date and time.
SV-276645r1139457_ruleSamsung Android must be configured to enable authentication of personal hotspot connections to the device using a preshared key.
SV-276646r1139460_ruleSamsung Android's Work profile must be configured to disable exceptions to the access control policy that prevent application processes and groups of application processes from accessing all data stored by other application processes and groups of application processes.
SV-276647r1139463_ruleSamsung Android must be configured to disable developer modes.
SV-276648r1192660_ruleSamsung Android 16 must disable the ability of the user to wipe the device.
SV-276649r1139469_ruleSamsung Android must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including DOD-approved commercial app repository, management tool server, or mobile application store.
SV-276650r1139472_ruleSamsung Android must be configured to not allow backup of all applications and configuration data to remote systems. (This requirement applies to the Work Profile for COPE.) - Disable Data Sync Framework.
SV-276651r1139475_ruleSamsung Android's Work profile must be configured to prevent users from adding personal email accounts to the work email app.
SV-276652r1139478_ruleSamsung Android must be configured to enable encryption for data at rest on removable storage media or, alternately, the use of removable storage media must be disabled.
SV-276653r1139481_ruleSamsung Android 16 must disable wireless printing.
SV-276654r1139484_ruleSamsung Android must be configured to disable USB mass storage mode.
SV-276655r1139487_ruleSamsung Android must be configured to not allow backup of all applications and configuration data to locally connected systems.
SV-276656r1139490_ruleSamsung Android must be configured to disable ad hoc wireless client-to-client connection capability.
SV-276657r1140698_ruleThe Samsung Android device must be configured to enforce that Wi-Fi Sharing is disabled.
SV-276658r1139496_ruleSamsung Android's Work profile must have the DOD root and intermediate PKI certificates installed.
SV-276659r1139499_ruleThe Samsung Android device work profile must be configured to enforce the system application disable list.
SV-276660r1139502_ruleThe Samsung Android device work profile must be configured to disable automatic completion of work space internet browser text input.
SV-276661r1139505_ruleSamsung Android must not accept the certificate when it cannot establish a connection to determine the validity of a certificate.
SV-276662r1139508_ruleSamsung Android's Work profile must be configured to enable Common Criteria (CC) mode.
SV-276663r1139511_ruleSamsung Android must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device.
SV-276664r1139514_ruleSamsung Android must be configured to disable authentication mechanisms providing user access to protected data other than a Password Authentication Factor: Face recognition.
SV-276665r1139517_ruleSamsung Android must be configured to enable a screen-lock policy that will lock the display after a period of inactivity - Disable trust agents.
SV-276666r1139520_ruleSamsung Android must be configured to not display the following (Work Environment) notifications when the device is locked: All notifications.
SV-276667r1139523_ruleSamsung Android must be configured to not allow more than 10 consecutive failed authentication attempts.
SV-276668r1139526_ruleSamsung Android must be configured to lock the display after 15 minutes (or less) of inactivity.
SV-276669r1139529_ruleThe Samsung Android device must be configured to perform the following management function: Disable Phone Hub.
SV-276670r1139532_ruleSamsung Android must be configured to enforce a minimum password length of six characters.
SV-276671r1139535_ruleSamsung Android must be configured to not allow passwords that include more than four repeating or sequential characters.
SV-276672r1139538_ruleThe Samsung Android device must be configured to disable the use of third-party keyboards.
SV-276673r1139778_ruleSamsung Android 16 must disable screen capture.
SV-276674r1139544_ruleSamsung Android's Work profile must be configured to enable audit logging.
SV-276675r1139547_ruleThe Samsung Android device must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].
SV-276676r1139550_ruleThe Samsung Android device must be configured to enable Certificate Revocation List (CRL) status checking.
SV-276677r1139553_ruleSamsung Android allowlist must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini.
SV-276722r1139688_ruleSamsung Android's Work profile must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: Names.
SV-276723r1139691_ruleSamsung Android's Work profile must be configured to not allow installation of applications with the following characteristics: - Back up MD data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmit MD diagnostic data to non-DOD servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with user; and - Allows unencrypted (or encrypted but not FIPS 140-2/140-3-validated) data sharing with other MDs or printers. - Apps that backup their own data to a remote system. - Apps that render TV shows and movies.
SV-276739r1139739_ruleSamsung Android must be enrolled as a COPE device.
SV-276740r1139774_ruleSamsung Android device users must complete required training.
SV-276741r1140694_ruleThe Samsung Android device must have the latest available Samsung Android operating system (OS) installed.
SV-276742r1139748_ruleThe Samsung Android device must be provisioned as a fully managed device and configured to create a work profile.
SV-276743r1139781_ruleSamsung Android 16 devices must have a Mobile Threat Detection (MTD) app installed.
SV-276744r1139780_ruleSamsung Android 16 must implement the management setting: disable Camera.
SV-279247r1140700_ruleThe Samsung Android device must be configured to disable Wi-Fi Aware for Work Profile apps.