STIGQter STIGQter: STIG Summary:

Zebra Technologies Android 14 COPE Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 13 May 2026

CheckedNameTitle
SV-283584r1190163_ruleZebra Android 14 must be configured to enable audit logging.
SV-283609r1190238_ruleZebra Android 14 must be configured to enforce a minimum password length of six characters.
SV-283610r1190241_ruleZebra Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters.
SV-283611r1190244_ruleZebra Android 14 must be configured to lock the display after 15 minutes (or less) of inactivity.
SV-283612r1190247_ruleZebra Android 14 must be configured to not allow more than 10 consecutive failed authentication attempts.
SV-283613r1190250_ruleZebra Android 14 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store].
SV-283614r1190253_ruleZebra Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].
SV-283615r1190256_ruleZebra Android 14 allowlist must be configured to not include applications with the following characteristics: - Backs up mobile device (MD) data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DOD servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with user; - Payment processing; - Allows unencrypted (or encrypted but not FIPS 140-2/140-3 validated) data sharing with other MDs or printers; - Backs up own data to a remote system; - Renders TV shows and movies.
SV-283616r1190259_ruleZebra Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
SV-283620r1190271_ruleZebra Android 14 must be configured to disable trust agents.
SV-283622r1190277_ruleZebra Android 14 must be configured to disable developer modes.
SV-283625r1190286_ruleZebra Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device.
SV-283626r1190289_ruleZebra Android 14 must be configured to generate audit records for the following auditable events: Detected integrity violations.
SV-283630r1190301_ruleZebra Android 14 must be configured to disable USB mass storage mode.
SV-283631r1190304_ruleZebra Android 14 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.
SV-283632r1190307_ruleZebra Android 14 must be configured to not allow backup of [all applications, configuration data] to remote systems.
SV-283633r1190310_ruleZebra Android 14 must be configured to enable authentication of personal hotspot connections to the device using a preshared key.
SV-283635r1190316_ruleZebra Android 14 must be configured to disable exceptions to the access control policy that prevent [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].
SV-283636r1190319_ruleZebra Android 14 must be configured to disable multiuser modes.
SV-283640r1190331_ruleZebra Android 14 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile).
SV-283641r1190334_ruleZebra Android 14 must be configured to disable ad hoc wireless client-to-client connection capability.
SV-283643r1190340_ruleZebra Android 14 users must complete required training.
SV-283644r1190343_ruleZebra Android 14 must be configured to enforce that Wi-Fi Sharing is disabled.
SV-283645r1190346_ruleZebra Android 14 must have the DOD root and intermediate PKI certificates installed.
SV-283646r1190349_ruleThe Zebra Android 14 work profile must be configured to prevent users from adding personal email accounts to the work email app.
SV-283647r1190352_ruleThe Zebra Android 14 work profile must be configured to enforce the system application disable list.
SV-283648r1190355_ruleZebra Android 14 must be provisioned as a fully managed device and configured to create a work profile.
SV-283649r1190358_ruleThe Zebra Android 14 work profile must be configured to disable automatic completion of workspace internet browser text input.
SV-283650r1190361_ruleThe Zebra Android 14 work profile must be configured to disable the autofill services.
SV-283651r1190364_ruleZebra Android 14 must be configured to disallow configuration of date and time.
SV-283653r1190370_ruleZebra Android 14 devices must have the latest available Zebra Android 14 operating system installed.
SV-283654r1190373_ruleAndroid 14 devices must be configured to disable the use of third-party keyboards.
SV-283655r1190376_ruleAndroid 14 devices must be configured to enable Common Criteria mode (CC mode).
SV-283656r1190379_ruleZebra Android 14 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].
SV-283657r1190382_ruleZebra Android 14 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates.
SV-283658r1190385_ruleZebra Android 14 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub.
SV-283659r1190388_ruleZebra Android 14 must disable the user's ability to wipe the device.
SV-283660r1190391_ruleZebra Android 14 must disable the use of assistants (including Zebra Assistant) unless required to meet Section 508 compliance requirements.
SV-283661r1190394_ruleZebra Android 14 must disable wireless printing.
SV-283662r1190397_ruleZebra Android 14 must disable screen capture.
SV-283663r1190400_ruleZebra Android 14 devices must have a Mobile Threat Detection (MTD) app installed.
SV-283664r1190778_ruleZebra Android 14 must implement the management setting: disable Camera.