V-58783 | High | The LG Android 5.0 platform must be configured to enable data-at-rest protection for on-device storage. | The operating system must ensure the data being written to the mobile device's built-in storage media is protected from unauthorized access. If data at rest is unencrypted, it is vulnerable to... |
V-58785 | High | The LG Android 5.0 platform must be configured to enable data-at-rest protection for removable storage media. | The operating system must ensure the data being written to the mobile device's removable media is protected from unauthorized access. If data at rest is unencrypted, it is vulnerable to... |
V-58829 | Medium | The LG Android 5.0 platform must be configured to implement management setting: disable screen mirroring. | Screen mirroring allows the user to display device content to a compatible device (e.g., TV) over a Wi-Fi connection. Although this feature uses HDCP 2.x protocol and encryption of visual data to... |
V-58803 | Medium | The LG Android 5.0 platform must not allow Google crash report. | The sending of diagnostic data back to the manufacturer is prohibited in the DoD. Sending this data to an organization other than DoD is termed a “phone-home” vulnerability. This setting may... |
V-58809 | Medium | The LG Android 5.0 platform must not allow use of a voice assistant service. | On MOS devices, users (may be able to) access the device's contact database or calendar to obtain phone numbers and other information using a human voice even when the mobile device is locked.... |
V-58807 | Medium | The LG Android 5.0 platform must not display notifications with sensitive DoD information when the device is locked: calendar notifications. | If the mobile operating system were to display notifications or calendar information on the lock screen, an adversary may be able to gather sensitive data without needing to Unlock the device.... |
V-58805 | Medium | The LG Android 5.0 platform must not display notifications with sensitive DoD information when the device is locked: disable contact info. | If the mobile operating system were to display notifications or calendar information on the lock screen, an adversary may be able to gather sensitive data without needing to Unlock the device.... |
V-58825 | Medium | The LG Android 5.0 platform must be configured to implement the management settings: disable Android Beam. | Android Beam provides the capability for Android devices to transfer data between them. Data transfer is not encrypted using FIPS-validated encryption mechanisms. Sensitive DoD information could... |
V-58801 | Medium | The LG Android 5.0 platform must be configured to implement the management setting: disable LG Backup. | A cloud backup feature may gather a user's information, such as PII, or sensitive documents. With this feature enabled, sensitive information will be backed up to the manufacturer's servers and... |
V-58851 | Medium | The LG Android 5.0 platform must be configured to implement the management setting: Disable native Android email client. | The native email client includes encryption modules that are not FIPS 140-2 validated. DoD policy requires all encryption modules used in DoD IT systems be FIPS 140-2 validated.
SFR ID:... |
V-58821 | Medium | The LG Android 5.0 platform must disable split-tunneling on the VPN client. | Spilt-tunneling allows multiple simultaneous remote connections to the mobile device. Without VPN split-tunneling disabled, malicious applications can covertly off-load device data to a... |
V-58837 | Medium | The LG Android 5.0 platform must be configured to disable download mode. | Download mode allows the firmware of the device to be flashed (updated) by the user. All updates should be controlled by the system administrator to ensure configuration control of the security... |
V-58791 | Medium | The LG Android 5.0 platform must be configured to fully wipe protected data upon unenrollment from the MDM. | When a mobile device is no longer going to be managed by MDM technologies, its protected/sensitive data must be sanitized because it will no longer be protected by the MDM software, so it is at... |
V-58835 | Medium | The LG Android 5.0 platform must be configured to implement the management setting: disable all Bluetooth profiles except for HSP (Headset Profile) and HFP (Hands-Free Profile). | Unsecure Bluetooth profiles may allow either unauthenticated connections to mobile devices or transfer of sensitive DoD data without required DoD information assurance (IA) controls. Only the HSP... |
V-58797 | Medium | The LG Android 5.0 platform must not allow the device unlock password to contain more than two repeating characters (e.g., 444, aaa). | Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute-force attack. Passwords with sequential or repeating numbers or alphabetic... |
V-58833 | Medium | The LG Android 5.0 platform must be configured to disable the capability for an operating system update to be automatically downloaded and installed on the mobile device. | FOTA allows the user to download and install firmware updates over-the-air. These updates can include OS upgrades, security patches, bug fixes, new features and applications. Since the updates are... |
V-58795 | Medium | The LG Android 5.0 platform must not allow the device unlock password to contain more than two sequential characters (e.g., 456, abc). | Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute-force attack. Passwords with sequential or repeating numbers or alphabetic... |
V-58831 | Medium | The LG Android 5.0 platform must be configured to enforce an application launching policy through an application blacklist specifying a set of disallowed applications: disable unapproved core and preinstalled applications. | Applications from various sources (including the vendor, the carrier, and Google) are preinstalled on the device at the time of manufacture. Some of the applications can compromise DoD data or... |
V-58799 | Medium | The LG Android 5.0 platform must be configured to implement the management setting: disable Google Backup. | A cloud backup feature may gather a user's information, such as PII, or sensitive documents. With this feature enabled, sensitive information will be backed up to the manufacturer's servers and... |
V-58823 | Medium | The LG Android 5.0 platform must be configured to implement the management settings: disable NFC. | NFC provides the capability for Android devices to transfer data between them. Data transfer is not encrypted using FIPS-validated encryption mechanisms. Sensitive DoD information could be... |
V-58839 | Medium | The LG Android 5.0 platform must be managed by an MDM. | Security-related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not... |
V-58819 | Medium | The LG Android 5.0 platform must not allow a user to remove security configuration profiles enforcing DoD security requirements. | Configuration profiles define security policies on MOS devices. If a user is able to remove a configuration profile, the user can then change the configuration that had been enforced by that... |
V-58815 | Medium | The LG Android 5.0 platform must not allow Google Auto sync. | Synchronization of data between devices associated with one user permits a user of an MOS device to transition user activities from one device to another. This feature passes sufficient... |
V-58771 | Medium | The LG Android 5.0 platform must be configured to lock the display after 15 minutes (or less) of inactivity. | The screen lock timeout must be set to a value that helps protect the device from unauthorized access. Having a too-long timeout would increase the window of opportunity for adversaries who gain... |
V-58775 | Medium | The LG Android 5.0 platform must be configured to enforce an application installation policy by specifying one or more authorized application repositories: disable Google Play. | Forcing all applications to be installed from authorized application repositories can prevent unauthorized and malicious applications from being installed and executed on mobile devices. Allowing... |
V-58827 | Medium | The LG Android 5.0 platform must be configured to implement the management settings: disable Wi-Fi Direct. | Wi-Fi Direct allows the device to connect directly to another device via Wi-Fi without accessing a Wi-Fi access point and using DoD-required security mechanisms since Wi-Fi Direct can be used by... |
V-58777 | Medium | The LG Android 5.0 platform must be configured to enforce an application installation policy by specifying one or more authorized application repositories: disable unknown source. | Forcing all applications to be installed from authorized application repositories can prevent unauthorized and malicious applications from being installed and executed on mobile devices. Allowing... |
V-58779 | Medium | The LG Android 5.0 platform must be configured to enforce an application installation policy through an application whitelist specifying a set of allowed applications and versions. | Requiring all authorized applications to be in an application whitelist prevents the execution of any applications (e.g., unauthorized, malicious) that are not part of the whitelist. Failure to... |
V-58843 | Medium | The LG Android 5.0 platform must be configured to implement the management setting: disable Allow System Time Changes. | Determining the correct time a particular application event occurred on a system is critical when conducting forensic analysis and investigating system events.
Periodically synchronizing... |
V-58781 | Medium | The LG Android 5.0 platform must be configured to disable developer modes. | Developer modes circumvent certain security measures, so their use for standard operation is not recommended. Developer modes may increase the likelihood of compromise of confidentiality,... |
V-58841 | Medium | The LG Android 5.0 platform must be configured to enable CC Mode. | CC mode implements several security controls required by the Mobile Device Functional Protection Profile (MDFPP). If CC mode is not implemented, DoD data is more at risk of being compromised, and... |
V-58847 | Medium | The LG Android 5.0 platform must disable Android Smart Lock. | Android Smart Lock provides the capability for the user to unlock the device using non-approved methods, including having a "trusted" device nearby, trusted face viewing the screen, or by swiping... |
V-58789 | Medium | The LG Android 5.0 platform must be configured to disable USB. | This data transfer capability could allow users to transfer sensitive DoD data onto unauthorized USB storage devices, thus leading to the compromise of this DoD data.
SFR ID: FMT_SMF.1.1 #41 |
V-58849 | Medium | The LG Android 5.0 platform must be configured to implement the management setting: Disable native Android browser. | The native browser includes encryption modules that are not FIPS 140-2 validated. DoD policy requires all encryption modules used in DoD IT systems be FIPS 140-2 validated.
SFR ID: FMT_MOF.1.1(2) #13 |
V-58769 | Low | The LG Android 5.0 platform must be configured to enforce a minimum password length of 6 characters. | Password strength is a measure of the effectiveness of a password in resisting guessing and brute force attacks. The ability to crack a password is a function of how many attempts an adversary is... |
V-58817 | Low | The LG Android 5.0 platform must retain the notice and consent banner on the screen until the user executes a positive action to manifest agreement by selecting a box indicating acceptance. | To ensure notice of and consent to the terms of the DoD standard user agreement, an Android app must display a consent banner. Additionally, the app must prevent further activity in the... |
V-58773 | Low | The LG Android 5.0 platform must be configured to prohibit more than 10 consecutive failed authentication attempts. | Users must not be able to override the system policy on the maximum number of consecutive failed authentication attempts because this could allow them to raise the maximum, thus giving adversaries... |
V-58845 | Low | The LG Android 5.0 platform must not allow the user to modify Owner Info on the device screen. | The Owner Info screen may contain required information, including a phone number to call if a device is lost, or the DoD Warning Banner. The ability of the device user to modify the Set Owner... |
V-58787 | Low | The LG Android 5.0 platform must be configured to require the user to manifest consent to the terms of the DoD-specified warning banner each time the user boots the device. | The mobile operating system is required to display the DoD-approved system use notification message or banner before granting access to the system that provides privacy and security notices... |