Google Android 15 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
medium | V-267560 | PP-MDF-993300 | GOOG-15-012200 | SV-267560r1033080_rule | 2024-12-05 | 1 |
Description |
---|
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFRID: FMT_MOF_EXT.1.2 #24 |
ℹ️ Check |
---|
Review the device configuration to confirm that the USB port is disabled except for charging the device. On the EMM console: 1. Open "Set user restrictions". 2. Verify "Disallow USB file transfer" is set to "ON". If on EMM console the USB port is not disabled ("Disallow USB file transfer" is set to "ON"), this is a finding. |
✔️ Fix |
---|
Configure Google Android 15 device to disable the USB port (except for charging the device). COPE and COBO: On the EMM console: 1. Open "Set user restrictions". 2. Toggle "Disallow USB file transfer" to "ON". |