STIGQter STIGQter: STIG Summary: Samsung Android OS 9 with Knox 3.x COBO Use Case KPE(Legacy) Deployment Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 25 Oct 2019

CheckedNameTitle
SV-103041r1_ruleSamsung Android must be configured to prevent users from adding personal email accounts to the work email app.
SV-103043r1_ruleSamsung Android must be configured to enforce the system application disable list.
SV-103045r1_ruleSamsung Android must be configured to enforce an application installation policy by specifying an application whitelist that restricts applications by the following characteristics: list of digital signatures, list of package names.
SV-103047r1_ruleThe Samsung Android whitelist must be configured to not include applications with the following characteristics: - back up mobile device data to non-DoD cloud servers (including user and application access to cloud backup services); - transmit mobile device diagnostic data to non-DoD servers; - voice assistant application if available when the mobile device is locked; - voice dialing application if available when the mobile device is locked; - allows synchronization of data or applications between devices associated with the user; and - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other mobile devices or printers.
SV-103655r1_ruleSamsung Android must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [DoD-approved commercial app repository, MDM server, mobile application store]: - disallow unknown app installation sources.
SV-103659r1_ruleSamsung Android must be configured to enable the Knox audit log.
SV-103661r1_ruleSamsung Android must be configured to not display the following notifications when the device is locked: all notifications.
SV-103663r1_ruleSamsung Android device users must complete required training.
SV-103665r1_ruleAny accessory that provides wired networking capabilities to a Samsung Android device must not be connected to a DoD network (for example: DeX Station [LAN port], USB to Ethernet adapter, etc.).
SV-103667r1_ruleSamsung Android must be configured to enforce a minimum password length of six characters.
SV-103669r1_ruleSamsung Android must be configured to not allow passwords that include more than two repeating or sequential characters.
SV-103671r1_ruleSamsung Android must be configured to lock the display after 15 minutes (or less) of inactivity.
SV-103673r1_ruleSamsung Android must be configured to not allow more than 10 consecutive failed authentication attempts.
SV-103675r1_ruleSamsung Android must be configured to disable trust agents. Note: This requirement is not applicable (NA) for specific biometric authentication factors included in the products Common Criteria evaluation.
SV-103677r1_ruleSamsung Android must be configured to disable Face Recognition. Note: This requirement is not applicable (NA) for specific biometric authentication factors included in the products Common Criteria evaluation.
SV-103679r1_ruleSamsung Android must be configured to disable automatic completion of Samsung Internet browser text input.
SV-103681r1_ruleSamsung Android must be configured to disable multi-user modes.
SV-103683r1_ruleSamsung Android must be configured to disable all Bluetooth profiles except HSP (Headset Profile), HFP (HandsFree Profile), and SPP (Serial Port Profile).
SV-103685r1_ruleSamsung Android must be configured to disable USB mass storage mode.
SV-103687r1_ruleSamsung Android must be configured to enable Knox Common Criteria (CC) Mode.
SV-103689r1_ruleSamsung Android must be configured to disallow configuration of date and time.
SV-103691r1_ruleSamsung Android must be configured to enforce a USB host mode exception list. Note: This configuration allows DeX mode (with input devices), which is DoD-approved for use.
SV-103693r1_ruleSamsung Android must be configured to disable the Share Via List feature.
SV-103695r1_ruleSamsung Android must be configured to disallow outgoing beam.
SV-103697r1_ruleSamsung Android must be configured to enforce that Wi-Fi Sharing is disabled.
SV-103699r1_ruleSamsung Android must be configured to not allow backup of [all applications, configuration data] to locally connected systems.
SV-103701r1_ruleSamsung Android must be configured to not allow backup of [all applications, configuration data] to remote systems.
SV-103703r1_ruleSamsung Android must be configured to disable developer modes.
SV-103705r1_ruleSamsung Android must be configured to enable authentication of personal hotspot connections to the device using a preshared key.
SV-103707r1_ruleSamsung Android must be configured to enable encryption for data at rest on removable storage media or alternately, the use of removable storage media must be disabled.
SV-103709r1_ruleSamsung Android must be configured to enable Certificate Revocation List (CRL) status checking.
SV-103711r1_ruleSamsung Android must have the DoD root and intermediate PKI certificates installed.
SV-103713r1_ruleSamsung Android must be configured to display the DoD advisory warning message at startup or each time the user unlocks the device.
SV-103715r1_ruleSamsung Android devices must have the latest available Samsung Android operating system installed.
SV-103717r1_ruleSamsung Android must be configured to enable the Online Certificate Status Protocol (OCSP).
SV-103719r1_ruleSamsung Android must be configured to not enable Microsoft Exchange ActiveSync (EAS) password recovery. This requirement is not applicable if not using Microsoft EAS.
SV-103721r1_ruleSamsung Android must be configured to set the password history with a length of 0.
SV-103723r1_ruleSamsung Android must be configured to enforce that Secure Startup is enabled. This requirement is Not Applicable (NA) to Galaxy S10 (or newer) devices.
SV-103725r2_ruleSamsung Android must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
SV-103727r1_ruleSamsung Android must be configured to enforce that Strong Protection is enabled. This requirement is Not Applicable (NA) for devices older than Galaxy S10.