{
"stig": {
"date": "2015-09-22",
"description": "This Interim Security Configuration Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.stig_spt@mail.mil.",
"findings": {
"V-58769": {
"checkid": "C-59613r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Password length\" setting in the MDM console.\n2. Verify the setting for the password length equals or is greater than the required length.\n\nOn The LG Android device:\n1. Unlock the device\n2. Navigate to the password entry screen: Settings >> Lockscreen >> Select screen lock >> Password\n3. Attempt to enter a password with a length less than the required value. \n\nIf the configured value of the \"Password length\" setting is less than the required length, or if device accepts a password of less than the required length, this is a finding.",
"description": "Password strength is a measure of the effectiveness of a password in resisting guessing and brute force attacks. The ability to crack a password is a function of how many attempts an adversary is permitted, how quickly an adversary can do each attempt, and the size of the password space. The longer the minimum length of the password is, the larger the password space. Having a too-short minimum password length significantly reduces password strength, increasing the chance of password compromise and resulting device and data compromise.\n\nSFR ID: FMT_SMF.1.1 #01",
"fixid": "F-64153r1_fix",
"fixtext": "Configure the mobile device to enforce a minimum password length of 6 characters.\n\nOn the MDM Administration Console, set the \"Password length\" value to 6 or greater.",
"iacontrols": null,
"id": "V-58769",
"ruleID": "SV-73199r1_rule",
"severity": "low",
"title": "The LG Android 5.0 platform must be configured to enforce a minimum password length of 6 characters.",
"version": "LGA5-10-000100"
},
"V-58771": {
"checkid": "C-59615r3_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Maximum time to lock\" setting in the MDM console.\n2. Verify the value of the setting is 15 minutes or less.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the screen timeout setting: Settings >> Display >> Screen timeout \n3. Stop all activity on the device for 15 minutes.\n\nIf the \"maximum time to lock\" setting is not set to 15 minutes, or if the user does not have to unlock the device after 15 minutes of inactivity, this is a finding.",
"description": "The screen lock timeout must be set to a value that helps protect the device from unauthorized access. Having a too-long timeout would increase the window of opportunity for adversaries who gain physical access to the mobile device through loss, theft, etc. Such devices are much more likely to be in an unlocked state when acquired by an adversary, thus granting immediate access to the data on the mobile device. The maximum timeout period of 15 minutes has been selected to balance functionality and security; shorter timeout periods may be appropriate, depending on the risks posed to the mobile device.\n\nSFR ID: FMT_SMF.1.1 #02",
"fixid": "F-64155r1_fix",
"fixtext": "Configure the mobile device to lock the device display after 15 minutes (or less) of inactivity.\n\nOn the MDM Administration Console, set the \"Maximum time to lock\" value to 15 minutes (or less).",
"iacontrols": null,
"id": "V-58771",
"ruleID": "SV-73201r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to lock the display after 15 minutes (or less) of inactivity.",
"version": "LGA5-10-000200"
},
"V-58773": {
"checkid": "C-59617r1_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display \"Maximum failed password attempts\" setting in the MDM console.\n2. Verify the value is 10 or less.\n \nOn the LG Android device:\nNote: it is recommended that this procedure be performed only on a test device.\n1. Enter the wrong Password until the device performs a factory reset.\n2. Note the number of password attempts needed before the device performs a factory reset. \n\nIf the \"Maximum failed password attempts\" is not set to 10 or less or the device did not perform a factory reset before a wrong password was entered eleven times, this is a finding.",
"description": "Users must not be able to override the system policy on the maximum number of consecutive failed authentication attempts because this could allow them to raise the maximum, thus giving adversaries more chances to guess/brute-force passwords, which increases the risk of the mobile device being compromised. Therefore, only administrators should have the authority to set consecutive failed authentication attempt policies.\n\nSFR ID: FMT_SMF.1.1 #02",
"fixid": "F-64157r1_fix",
"fixtext": "Configure the mobile device to allow only 10 or less consecutive failed authentication attempts.\n\nOn the MDM Administration Console, set the \"Maximum failed password attempts\" value to 10 or less.",
"iacontrols": null,
"id": "V-58773",
"ruleID": "SV-73203r1_rule",
"severity": "low",
"title": "The LG Android 5.0 platform must be configured to prohibit more than 10 consecutive failed authentication attempts.",
"version": "LGA5-10-000300"
},
"V-58775": {
"checkid": "C-59619r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Google Play Store\" setting in the MDM console.\n2. Verify the setting is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the Play Store: Apps >> Play Store\n3. Verify Google Play Store application does not run.\n\nIf the \"Allow Google Play Store\" setting is enabled, or if the user is able to run the Google Play Store on the device, this is a finding.",
"description": "Forcing all applications to be installed from authorized application repositories can prevent unauthorized and malicious applications from being installed and executed on mobile devices. Allowing such installations and executions could cause a compromise of DoD data accessible by these unauthorized/malicious applications.\n\nSFR ID: FMT_SMF.1.1 #10",
"fixid": "F-64159r1_fix",
"fixtext": "Configure the mobile device to use one or more authorized application repositories. \n\nOn the MDM Administration Console, disable \"Google Play Store\".",
"iacontrols": null,
"id": "V-58775",
"ruleID": "SV-73205r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to enforce an application installation policy by specifying one or more authorized application repositories: disable Google Play.",
"version": "LGA5-10-000401"
},
"V-58777": {
"checkid": "C-59621r4_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow unknown sources\" setting in the MDM console.\n2. Verify the setting is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the \"Unknown sources\": Settings >> Security >> Unknown sources\n3. Verify \"Unknown sources\" setting is disabled. \n\nIf the \"Allow unknown sources\" setting is enabled, or if the user is able to install the unknown source application, this is a finding.",
"description": "Forcing all applications to be installed from authorized application repositories can prevent unauthorized and malicious applications from being installed and executed on mobile devices. Allowing such installations and executions could cause a compromise of DoD data accessible by these unauthorized/malicious applications.\n\nSFR ID: FMT_SMF.1.1 #10",
"fixid": "F-64161r2_fix",
"fixtext": "Configure the mobile device to use one or more authorized application repositories.\n\nOn the MDM Administration Console, disable \"Unknown Sources\".",
"iacontrols": null,
"id": "V-58777",
"ruleID": "SV-73207r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to enforce an application installation policy by specifying one or more authorized application repositories: disable unknown source.",
"version": "LGA5-10-000402"
},
"V-58779": {
"checkid": "C-59623r2_chk",
"checktext": "This validation procedure is performed on the MDM Administration Console.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Application whitelist configuration\" setting in the MDM console.\n2. Verify the \"Application whitelist configuration\" setting is enabled.\n3. Verify all applications on the list of white-listed applications have been approved by the Approving Official (AO).\n4. Verify the mobile device is on the list of managed devices in the MDM console.\n\nNote: This list can be empty if no applications have been approved.\n\nIf the \"Application whitelist configuration\" setting is disabled, or if applications listed in the MDM console \"Application whitelist configuration\" are not approved by the AO, this is a finding.",
"description": "Requiring all authorized applications to be in an application whitelist prevents the execution of any applications (e.g., unauthorized, malicious) that are not part of the whitelist. Failure to configure an application whitelist properly could allow unauthorized and malicious applications to be downloaded, installed, and executed on the mobile device, causing a compromise of DoD data accessible by these applications.\n\nSFR ID: FMT_SMF.1.1 #10",
"fixid": "F-64163r1_fix",
"fixtext": "Configure the mobile device to allow installing application based on whitelist.\n\nOn the MDM Administration Console, enable \"Application whitelist configuration\".",
"iacontrols": null,
"id": "V-58779",
"ruleID": "SV-73209r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to enforce an application installation policy through an application whitelist specifying a set of allowed applications and versions.",
"version": "LGA5-10-000500"
},
"V-58781": {
"checkid": "C-59625r3_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow development mode\" setting in the MDM console.\n2. Verify the setting is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to Settings >> About Phone >> Software info >> Build number.\n3. Push \"Build number\" multiple times until a pop-up menu display indicates developer option unavailable.\n\nIf the \"Allow development mode\" setting is enabled, or if the user is able to find the development mode on the device, this is a finding.",
"description": "Developer modes circumvent certain security measures, so their use for standard operation is not recommended. Developer modes may increase the likelihood of compromise of confidentiality, integrity, and availability.\n\nSFR ID: FMT_SMF.1.1 #20",
"fixid": "F-64165r1_fix",
"fixtext": "Configure the mobile device to disable developer modes.\n\nOn the MDM Administration Console, disable \"Developer Modes\".",
"iacontrols": null,
"id": "V-58781",
"ruleID": "SV-73211r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to disable developer modes.",
"version": "LGA5-10-000700"
},
"V-58783": {
"checkid": "C-59627r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Encryption\" setting in the MDM console.\n2. Verify \"Device Encryption\" is selected.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to: Settings >> Security >> Encrypt phone\n3. Verify \"Encrypt phone\" is enabled and cannot be disabled.\n\nIf the \"Device Encryption\" is not enabled, or if the user is able to disable the setting on the device, this is a finding.",
"description": "The operating system must ensure the data being written to the mobile device's built-in storage media is protected from unauthorized access. If data at rest is unencrypted, it is vulnerable to disclosure. Even if the operating system enforces permissions on data access, an adversary can read storage media directly, thereby circumventing operating system controls. Encrypting the data ensures confidentiality is protected even when the operating system is not running.\n\nSFR ID: FMT_SMF.1.1 #21",
"fixid": "F-64167r1_fix",
"fixtext": "Configure the mobile device to enable data-at-rest protection for on-device storage.\n\nOn the MDM Administration Console, enable \"Device Encryption\" for on-device storage.",
"iacontrols": null,
"id": "V-58783",
"ruleID": "SV-73213r1_rule",
"severity": "high",
"title": "The LG Android 5.0 platform must be configured to enable data-at-rest protection for on-device storage.",
"version": "LGA5-10-000800"
},
"V-58785": {
"checkid": "C-59629r3_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Encryption\" setting in the MDM console.\n2. Verify \"Storage Card Encryption\" is enabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to: Settings >> Security >> Encrypt SD card storage\n3. Verify \"Encrypt SD card storage\" is enabled and cannot be disabled.\n\nIf the \"Storage Card Encryption\" is not enabled, or if the user is able to disable the setting on the device, this is a finding.",
"description": "The operating system must ensure the data being written to the mobile device's removable media is protected from unauthorized access. If data at rest is unencrypted, it is vulnerable to disclosure. Even if the operating system enforces permissions on data access, an adversary can read removable media directly, thereby circumventing operating system controls. Encrypting the data ensures confidentiality is protected even when the operating system is not running.\n\nSFR ID: FMT_SMF.1.1 #22",
"fixid": "F-64169r1_fix",
"fixtext": "Configure the mobile device to enable data-at-rest protection for removable media.\n\nOn the MDM Administration Console, enable \"Storage Card Encryption\" for removable media.",
"iacontrols": null,
"id": "V-58785",
"ruleID": "SV-73215r1_rule",
"severity": "high",
"title": "The LG Android 5.0 platform must be configured to enable data-at-rest protection for removable storage media.",
"version": "LGA5-10-000900"
},
"V-58787": {
"checkid": "C-59631r2_chk",
"checktext": "Note: the following procedure is exactly the same as requirement LGA5-20-001300. The procedure only needs to be performed once.\n\nThis validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Enforce warning banner\" setting in the MDM console.\n2. Verify the Enforce warning banner has been set up and the wording is exactly as specified in the Vulnerability Discussion.\n\nOn the LG Android device:\n1. Reboot the device and verify the warning banner is displayed.\n2. Verify the required text is displayed and the user must click \"Agree\" after checking \"I understand and agree to this\".\n\nIf the \"Enforce warning banner\" setting is not set, does not show the required text, or if device does not show the Warning banner after every device reboot, this is a finding.",
"description": "The mobile operating system is required to display the DoD-approved system use notification message or banner before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. Required banners help ensure that DoD can audit and monitor the activities of mobile device users without legal restriction. \n\nSystem use notification messages can be displayed when individuals first access or unlock the mobile device. The banner shall be implemented as a \"click-through\" banner at device unlock (to the extent permitted by the operating system). A \"click through\" banner prevents further activity on the information system unless and until the user executes a positive action to manifest agreement by clicking on a box indicating \u201cOK.\u201d\n\nThe approved DoD text must be used exactly as specified in the DoDI 8500.01. For devices accommodating banners of 1300 characters, the banner text is: \n\nYou are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. \nBy using this IS (which includes any device attached to this IS), you consent to the following conditions: \n-The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. \n-At any time, the USG may inspect and seize data stored on this IS. \n-Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. \n-This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. \n-Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details.\n\nFor Blackberries and other PDAs/PEDs with severe character limitations, the banner text is: \n\nI've read & consent to terms in IS user agreem't.\n\nThe administrator must configure the banner text exactly as written without any changes.\n\nSFR ID: FMT_SMF.1.1 #24",
"fixid": "F-64171r1_fix",
"fixtext": "Note: the following procedure is exactly the same as requirement LGA5-20-001300. The procedure only needs to be performed once.\n\nConfigure the mobile device to enforce warning banner.\n\nOn the MDM Administration Console, set the \"Enforce warning banner\" with the required text.",
"iacontrols": null,
"id": "V-58787",
"ruleID": "SV-73217r1_rule",
"severity": "low",
"title": "The LG Android 5.0 platform must be configured to require the user to manifest consent to the terms of the DoD-specified warning banner each time the user boots the device.",
"version": "LGA5-10-001100"
},
"V-58789": {
"checkid": "C-59633r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow USB\" setting in the MDM console.\n2. Verify the setting is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Connect device to test PC using USB cable.\n3. Navigate to the PC connection: Open device Notification bar >> select USB connected. \n4. Verify all USB connection types, except for \"Charge only\", are disabled and cannot be enabled.\n\nSince the USB storage and USB media player cannot be used, the USB function is only available for device charging.\n\nIf the \"Allow USB\" setting is enabled or if the user is able to enable the setting on the device, this is a finding.",
"description": "This data transfer capability could allow users to transfer sensitive DoD data onto unauthorized USB storage devices, thus leading to the compromise of this DoD data.\n\nSFR ID: FMT_SMF.1.1 #41",
"fixid": "F-64173r1_fix",
"fixtext": "Configure the mobile device to disable data transfer capabilities through USB.\n\nOn the MDM Administration Console, disable \"Allow USB\".",
"iacontrols": null,
"id": "V-58789",
"ruleID": "SV-73219r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to disable USB.",
"version": "LGA5-10-001200"
},
"V-58791": {
"checkid": "C-59635r1_chk",
"checktext": "This validation procedure is performed on the MDM Administration Console.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to verify on the MDM console the \"Device + SD Card Wipe\" setting is automatically implemented upon unenrollment of the device from the MDM.\n\nIf the \"Device + SD Card Wipe\" setting is not enabled upon device unenrollment from the MDM, this is a finding.",
"description": "When a mobile device is no longer going to be managed by MDM technologies, its protected/sensitive data must be sanitized because it will no longer be protected by the MDM software, so it is at much greater risk of unauthorized access and disclosure.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64175r1_fix",
"fixtext": "Configure the mobile device to wipe protected data from the device when it is unenrolled from MDM. \n\nOn the MDM Administration Console, set the MDM to automatically enable the \"Device + SD Card Wipe\" when the device is unenrolled from the MDM.",
"iacontrols": null,
"id": "V-58791",
"ruleID": "SV-73221r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to fully wipe protected data upon unenrollment from the MDM.",
"version": "LGA5-10-001300"
},
"V-58795": {
"checkid": "C-59639r3_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Max Sequential Characters\" in the MDM console.\n2. Verify the setting is the same or less than the required length.\n\nOn The LG Android 5.0 platform device:\n1. Unlock the device\n2. Navigate to the password entry screen: Settings >> Lockscreen >> Select screen lock >> Password\n3. Attempt to enter a password with more than two sequential characters (letters or numbers). Determine if the new password is allowed. \n\nIf the configured values of the \u201cMax Sequential Character\u201d setting are greater than the required length, or if device accepts a password that contains sequential characters of length greater than the required length, this is a finding.",
"description": "Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute-force attack. Passwords with sequential or repeating numbers or alphabetic characters (e.g., 456, 987, 222, abc, ddd) are considered easier to crack than random patterns. Therefore, disallowing sequential or repeating numbers or alphabetic characters makes it more difficult for an adversary to discover the password.\n\nSFR ID: FMT_SMF_EXT.1",
"fixid": "F-64179r1_fix",
"fixtext": "Configure the mobile device to enforce a sequential password length of no more than 2 characters.\n\nOn the MDM Administration Console, set the \"Max Sequential Characters\" value to 2.",
"iacontrols": null,
"id": "V-58795",
"ruleID": "SV-73225r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must not allow the device unlock password to contain more than two sequential characters (e.g., 456, abc).",
"version": "LGA5-20-000101"
},
"V-58797": {
"checkid": "C-59641r3_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Max Repeating Characters\" setting in the MDM console.\n2. Verify the setting is the same or less than the required length.\n\nOn The LG Android 5.0 platform device:\n1. Unlock the device\n2. Navigate to the password entry screen: Settings >> Lockscreen >> Select screen lock >> Password \n3. Attempt to enter a password with more than two repeating characters. Determine if the new password is allowed. \n\nIf the configured values of the \u201cMax Repeating Characters\u201d setting are greater than the required length, or if device accepts a password that contains repeating characters of length greater than the required length, this is a finding.",
"description": "Password complexity or strength refers to how difficult it is to determine a password using a dictionary or brute-force attack. Passwords with sequential or repeating numbers or alphabetic characters (e.g., 456, 987, 222, abc, ddd) are considered easier to crack than random patterns. Therefore, disallowing sequential or repeating numbers or alphabetic characters makes it more difficult for an adversary to discover the password.\n\nSFR ID: FCS",
"fixid": "F-64181r1_fix",
"fixtext": "Configure the mobile device to enforce a repeated password length of no more than 2 characters.\n\nOn the MDM Administration Console, set the \"Max Repeating Characters\" value to 2.",
"iacontrols": null,
"id": "V-58797",
"ruleID": "SV-73227r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must not allow the device unlock password to contain more than two repeating characters (e.g., 444, aaa).",
"version": "LGA5-20-000102"
},
"V-58799": {
"checkid": "C-59643r3_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Google Backup\" settings in MDM console. \n2. Verify the setting is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the Backup & reset: Settings >> Backup & reset\n3. Verify \"Back up my data\" is disabled and cannot be enabled.\n\nIf the \"Allow Google Backup\" setting is enabled, or if the user is able to enable the setting on the device, this is a finding.",
"description": "A cloud backup feature may gather a user's information, such as PII, or sensitive documents. With this feature enabled, sensitive information will be backed up to the manufacturer's servers and database. This data is stored at a location that has unauthorized employees accessing this data. This data is stored on a server that has a location unknown to the DoD. Disabling this feature mitigates the risk of a backup feature that stores sensitive data on a server that has the potential to be located in a country other than the United States.\n\nSFR ID: FCS_STG_EXT.1.4",
"fixid": "F-64183r1_fix",
"fixtext": "Configure the mobile device to disable Google Backup.\n\nOn the MDM Administration Console, disable the \"Allow Google Backup\" setting.",
"iacontrols": null,
"id": "V-58799",
"ruleID": "SV-73229r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management setting: disable Google Backup.",
"version": "LGA5-20-000301"
},
"V-58801": {
"checkid": "C-59645r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow LG Backup\" settings in the MDM console. \n2. Verify the setting is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the Backup & reset: Settings >> Backup & reset\n3. Verify \"Back up my data\" is disabled and cannot be enabled.\n\nIf the \"Allow LG Backup\" setting is enabled, or if the user is able to enable the setting on the device, this is a finding.",
"description": "A cloud backup feature may gather a user's information, such as PII, or sensitive documents. With this feature enabled, sensitive information will be backed up to the manufacturer's servers and database. This data is stored at a location that has unauthorized employees accessing this data. This data is stored on a server that has a location unknown to the DoD. Disabling this feature mitigates the risk of a backup feature that stores sensitive data on a server that has the potential to be located in a country other than the United States.\n\nSFR ID: FIA_AFL_EXT.1.2",
"fixid": "F-64185r1_fix",
"fixtext": "Configure the mobile device to disable LGBackup.\n\nOn the MDM Administration Console, disable the \"Allow LG Backup\" setting.",
"iacontrols": null,
"id": "V-58801",
"ruleID": "SV-73231r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management setting: disable LG Backup.",
"version": "LGA5-20-000302"
},
"V-58803": {
"checkid": "C-59647r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Google crash report\" setting in the MDM console.\n2. Verify the Google crash report is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the Google crash report: Settings >> Developer Options >> check \"Power menu bug reports\" box >> press and hold power button to display Phone options.\n3. Click bug report\n4. Press \"Report\"\n5. Verify pop-up message that Google crash reports cannot be used.\n\nNote: If \"Developer mode\" is disabled, \"bug report\" is not available and the requirement has been met.\n\nIf the \"Allow Google crash report\" setting is enabled, or if the user is able to enable the setting on the device, this is a finding.",
"description": "The sending of diagnostic data back to the manufacturer is prohibited in the DoD. Sending this data to an organization other than DoD is termed a \u201cphone-home\u201d vulnerability. This setting may enable the device manufacturer to gather sensitive location data or other information about the user\u2019s practices. This data will be sent to the manufacturer's servers and database. This data is stored at a location which has unauthorized employees accessing this data. By disabling this feature, the phone-home risk will be mitigated.\n\nSFR ID: FMT_MOF.1.1(2) #08",
"fixid": "F-64187r1_fix",
"fixtext": "Configure the mobile device to disable Google crash report.\n\nOn the MDM Administration Console, disable the \"Allow Google crash report\" setting.",
"iacontrols": null,
"id": "V-58803",
"ruleID": "SV-73233r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must not allow Google crash report.",
"version": "LGA5-20-000400"
},
"V-58805": {
"checkid": "C-59649r1_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Contact info Access on lockscreen\" setting in the MDM console.\n2. Verify the setting is disabled.\n\nOn the LG Android 5.0 platform device:\n1. Unlock the device\n2. Add a phone number in the Contacts with contact name.\n3. Lock the LG device.\n4. Call the LG device from another phone.\n5. Verify the LG device displays the incoming call phone number but not the contact name.\n\nIf \"Allow Contact info Access on lockscreen\" setting on the MDM is not set correctly, or if the contact name is displayed on the locked screen for a received call on the LG device, this is a finding.",
"description": "If the mobile operating system were to display notifications or calendar information on the lock screen, an adversary may be able to gather sensitive data without needing to Unlock the device. This adversary may use this gathered intelligence to plan future attacks and possibly a physical attack. By disabling notifications on the lock screen, this prevents sensitive data from being displayed openly on the device\u2019s lock screen.\n\nSFR ID: FMT_MOF.1.1(2) #12",
"fixid": "F-64189r1_fix",
"fixtext": "Configure the mobile device to disable contact info access on lockscreen.\n\nOn the MDM Administration Console, set the \"Allow Contact info Access on lockscreen\" to disable.",
"iacontrols": null,
"id": "V-58805",
"ruleID": "SV-73235r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must not display notifications with sensitive DoD information when the device is locked: disable contact info.",
"version": "LGA5-20-000502"
},
"V-58807": {
"checkid": "C-59651r1_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Keyguard\" setting in the MDM console.\n2. Verify \"All\" is selected in the \"Keyguard Disabled\" screen.\n\nOn the LG Android device:\n1. Unlock the device\n2. Add a calendar event for the current day on the device.\n3. Lock the device.\n4. Verify no notifications are displayed on the lockscreen of the LG device.\n\nIf the \"All\" Keyguard Disabled setting is not disabled, or if the device is able to display notifications, this is a finding.",
"description": "If the mobile operating system were to display notifications or calendar information on the lock screen, an adversary may be able to gather sensitive data without needing to Unlock the device. This adversary may use this gathered intelligence to plan future attacks and possibly a physical attack. By disabling notifications on the lock screen, this prevents sensitive data from being displayed openly on the device\u2019s lock screen.\n\nSFR ID: FMT_MOF.1.1(2) #13",
"fixid": "F-64191r1_fix",
"fixtext": "Configure the mobile device to disable the keyguard All setting.\n\nOn the MDM Administration Console, disable \"All\" for the Keyguard Disabled setting.",
"iacontrols": null,
"id": "V-58807",
"ruleID": "SV-73237r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must not display notifications with sensitive DoD information when the device is locked: calendar notifications.",
"version": "LGA5-20-000600"
},
"V-58809": {
"checkid": "C-59653r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow voice command\" setting in the MDM console.\n2. Verify voice command application is disabled. \n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the \"Voice Command\": Apps >> Tools (Verizon only) >> Voice command.\n3. Verify voice command application does not run.\n\nIf the \"Allow voice command\" setting is enabled, or if the user is able to enable the setting on the device, this is a finding.",
"description": "On MOS devices, users (may be able to) access the device's contact database or calendar to obtain phone numbers and other information using a human voice even when the mobile device is locked. Often this information is personally identifiable information (PII), which is considered sensitive. It could also be used by an adversary to profile the user or engage in social engineering to obtain further information from other unsuspecting users. Disabling access to the contact database and calendar in these situations mitigates the risk of this attack. The AO may waive this requirement with written notice if the operational environment requires this capability.\n\nSFR ID: FMT_MOF.1.1(2) #14",
"fixid": "F-64193r1_fix",
"fixtext": "Configure the mobile device to disable running voice command application.\n\nOn the MDM Administration Console, disable the \"Allow voice command\" setting.",
"iacontrols": null,
"id": "V-58809",
"ruleID": "SV-73239r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must not allow use of a voice assistant service.",
"version": "LGA5-20-000700"
},
"V-58815": {
"checkid": "C-59659r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Auto Sync\" setting in the MDM console.\n2. Verify the setting \"Allow Auto Sync\" is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Open the device settings.\n3. Navigate to the Auto Sync setting: Settings >> Accounts (or Account & Sync) \n4. Verify the list of Auto-Sync data is disabled with the following message and cannot be unchecked.\n\u201cAuto Sync is disabled. Synchronization is enabled manually by server policy.\u201d\n\nIf the \"Allow Auto Sync\" setting is enabled, or if the user is able to enable the setting on the device, this is a finding.",
"description": "Synchronization of data between devices associated with one user permits a user of an MOS device to transition user activities from one device to another. This feature passes sufficient information between the devices to describe the activity, but app data synchronization associated with the activity is handled through cloud services, which should be disabled on a compliant MOS device. If a user associates both DoD and personal devices to the same Apple ID, the user may improperly reveal information about the nature of the user's activities on an unprotected device. Disabling this service mitigates this risk.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64199r1_fix",
"fixtext": "Configure the mobile device to disable Google auto sync.\n\nOn the MDM Administration Console, disable the \"Allow Auto Sync\" setting.",
"iacontrols": null,
"id": "V-58815",
"ruleID": "SV-73245r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must not allow Google Auto sync.",
"version": "LGA5-20-001100"
},
"V-58817": {
"checkid": "C-59661r2_chk",
"checktext": "Note: the following procedure is exactly the same as requirement LGA5-10-001100. The procedure only needs to be performed once.\n\nThis validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Enforce warning banner\" setting in the MDM console.\n2. Verify the Enforce warning banner has been set up and the wording is exactly as specified in the Vulnerability Discussion.\n\nOn the LG Android device:\n1. Reboot the device and verify the warning banner is displayed.\n2. Verify the required text is displayed and the user must click \"Agree\" after checking \"I understand and agree to this\".\n\nIf the \"Enforce warning banner\" setting is not set, does not show the required text, or if device does not show the Warning banner after every device reboot, this is a finding.",
"description": "To ensure notice of and consent to the terms of the DoD standard user agreement, an Android app must display a consent banner. Additionally, the app must prevent further activity in the application unless and until the user executes a positive action to manifest agreement, such as by tapping an acceptance button in the app. By preventing access to the system until the user accepts the conditions, legal requirements are met to protect the DoD and to remind users the device is designed and implemented for business use. Additional information is found in DoD Instruction 8500.01.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64201r1_fix",
"fixtext": "Configure the mobile device to enforce warning banner.\n\nOn the MDM Administration Console, set the \"Enforce warning banner\" with the required text.",
"iacontrols": null,
"id": "V-58817",
"ruleID": "SV-73247r1_rule",
"severity": "low",
"title": "The LG Android 5.0 platform must retain the notice and consent banner on the screen until the user executes a positive action to manifest agreement by selecting a box indicating acceptance.",
"version": "LGA5-20-001300"
},
"V-58819": {
"checkid": "C-59663r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Removal of device administrator rights\" setting in the MDM console.\n2. Verify the setting for the \"Removal of device administrator rights\" has been disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Open the device settings.\n3. Navigate to the Remove Device Admin rights setting: Settings >> Security >> Phone administrators\n4. Verify the list of Device Admin applications is disabled and cannot be unchecked. The following message may be displayed:\nRemoval of device administrator is disabled by server policy.\n\nIf the \"Removal of device administrator rights\" setting is enabled or if the user is able to enable the setting on the device, this is a finding.",
"description": "Configuration profiles define security policies on MOS devices. If a user is able to remove a configuration profile, the user can then change the configuration that had been enforced by that policy. Relaxing security policies may introduce vulnerabilities that the profiles had mitigated. Configuring a profile to never be removed mitigates this risk.\n\nSFR ID: FDP_IFC_EXT.1.1",
"fixid": "F-64203r1_fix",
"fixtext": "Configure the mobile device to disable removing device admin rights.\n\nOn the MDM Administration Console, disable \"Removal of device administrator rights\".",
"iacontrols": null,
"id": "V-58819",
"ruleID": "SV-73249r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must not allow a user to remove security configuration profiles enforcing DoD security requirements.",
"version": "LGA5-20-001400"
},
"V-58821": {
"checkid": "C-59665r6_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow VPN Split Tunneling\" setting in the MDM console.\n2. Verify the setting for the VPN Split Tunneling is disabled.\n\nOn the LG Android device:\n1. Unlock the device.\n2. Open the device settings.\n3. Navigate to the VPN Split Tunneling setting: \nSettings >> Tethering & Networks (or Wireless & Networks) >> VPN >> LG VPN >> add LG VPN network >> select \"Show advanced options\" popup >> \"Disable Split Tunneling\". Verify it is checked.\n\nIf the \"Allow VPN split tunneling\" setting is enabled, or if the user is able to change the \"Disable Split Tunneling\" setting on the device, this is a finding.",
"description": "Spilt-tunneling allows multiple simultaneous remote connections to the mobile device. Without VPN split-tunneling disabled, malicious applications can covertly off-load device data to a third-party server or set up a trusted tunnel between a non-DoD third-party server and a DoD network, providing a vector to attack the network.\n\nSFR ID: FPT_BBD_EXT.1.1",
"fixid": "F-64205r1_fix",
"fixtext": "Configure the mobile device to disable VPN split tunneling.\n\nOn the MDM Administration Console, disable the \"Allow VPN split tunneling\" setting.",
"iacontrols": null,
"id": "V-58821",
"ruleID": "SV-73251r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must disable split-tunneling on the VPN client.",
"version": "LGA5-20-001500"
},
"V-58823": {
"checkid": "C-59667r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow NFC\" setting in the MDM console.\n2. Verify the setting for the NFC is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the NFC setting: Settings >> Share & Connect >> NFC \n3. Verify the NFC menu is disabled and the following message is displayed: \nNFC is disabled by server policy.\n\nIf the \"Allow NFC\" setting is not disabled on the MDM console, or if the user is able to enable the NFC setting on the device, this is a finding.",
"description": "NFC provides the capability for Android devices to transfer data between them. Data transfer is not encrypted using FIPS-validated encryption mechanisms. Sensitive DoD information could be compromised if NFC is enabled.\n\nSFR ID: FPT_TST_EXT.2.2",
"fixid": "F-64207r1_fix",
"fixtext": "Configure the mobile device to disable NFC. \n\nOn the MDM Administration Console, disable the \"Allow NFC\" setting.",
"iacontrols": null,
"id": "V-58823",
"ruleID": "SV-73253r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management settings: disable NFC.",
"version": "LGA5-20-001701"
},
"V-58825": {
"checkid": "C-59669r3_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Android Beam\" setting in the MDM console.\n2. Verify the setting for the Android Beam is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Navigate to the Android Beam setting: Settings >> Share & Connect >> Android Beam\n3. Verify the Android Beam menu is disabled and the following message is displayed: \nAndroid Beam is disabled by server policy.\n\nIf the \"Allow Android Beam\" setting is enabled, or if the user is able to enable the setting on the device, this is a finding.",
"description": "Android Beam provides the capability for Android devices to transfer data between them. Data transfer is not encrypted using FIPS-validated encryption mechanisms. Sensitive DoD information could be compromised if Android beam is enabled.\n\nSFR ID: FPT_TUD_EXT.2.5",
"fixid": "F-64209r1_fix",
"fixtext": "Configure the mobile device to disable Android Beam. \n\nOn the MDM Administration Console, disable the \"Allow Android Beam\" setting.",
"iacontrols": null,
"id": "V-58825",
"ruleID": "SV-73255r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management settings: disable Android Beam.",
"version": "LGA5-20-001702"
},
"V-58827": {
"checkid": "C-59671r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Wi-Fi Direct\" setting in the MDM console.\n2. Verify the setting for the Wi-Fi Direct is disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Open the device settings.\n3. Navigate to the Wi-Fi Direct setting: Settings >> Wi-Fi >> Menu >> Advanced Wi-Fi >> click \"Wi-Fi Direct\"\n4. Verify the Wi-Fi Direct is disabled and the following message is displayed: \nWi-Fi Direct is disabled by server policy.\n\nIf the \"Allow Wi-Fi Direct\" setting is enabled, or if the user is able to enable the setting on the device, this is a finding.",
"description": "Wi-Fi Direct allows the device to connect directly to another device via Wi-Fi without accessing a Wi-Fi access point and using DoD-required security mechanisms since Wi-Fi Direct can be used by applications to exchange files between devices. Disabling this feature mitigates the risk of compromising sensitive DoD data.\n\nNote: Disabling Wi-Fi Direct also disables Miracast.\n\nSFR ID: FTA_TAB.1.1",
"fixid": "F-64211r1_fix",
"fixtext": "Configure the mobile device to disable Wi-Fi Direct.\n\nOn the MDM Administration Console, disable the \"Allow Wi-Fi Direct\" setting.",
"iacontrols": null,
"id": "V-58827",
"ruleID": "SV-73257r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management settings: disable Wi-Fi Direct.",
"version": "LGA5-20-001703"
},
"V-58829": {
"checkid": "C-59673r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Miracast\" setting in the MDM console.\n2. Verify the setting for the Miracast.\n\nOn the LG Android device:\n1. Unlock the device\n2. Open the device settings.\n3. Navigate to the Miracast setting: Settings >> Share & Connect >> Miracast \n4. Verify the Miracast menu is disabled and the following message is displayed: \nMiracast is disabled by server policy.\n\nIf the \"Allow Miracast\" setting is enabled, or if the user is able to enable the setting on the device, this is a finding.",
"description": "Screen mirroring allows the user to display device content to a compatible device (e.g., TV) over a Wi-Fi connection. Although this feature uses HDCP 2.x protocol and encryption of visual data to transmit data, vulnerabilities in the 2.0 and 2.1 protocol implementation can result in compromise of sensitive DoD data. Disabling this feature will mitigate this risk.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64213r1_fix",
"fixtext": "Configure the mobile device to disable Miracast.\n\nOn the MDM Administration Console, disable the \"Allow Miracast\" setting.",
"iacontrols": null,
"id": "V-58829",
"ruleID": "SV-73259r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement management setting: disable screen mirroring.",
"version": "LGA5-20-001800"
},
"V-58831": {
"checkid": "C-59675r1_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the list of unapproved core and preinstalled applications in the \"Application Blacklist (prevent launch of blacklist apps)\" setting in the MDM console.\n2. Verify the list contains all core and preinstalled applications not approved for DoD use by the Approving Official (AO). \nNote: Refer to the Supplemental document for additional information.\n\nOn the LG Android device:\n1. Attempt to launch an unapproved core and preinstalled application on the device.\n2. Verify the application will not run and the following message is displayed:\nApplication is disabled by server policy.\n\nIf the \"Allow Application Blacklist (prevent launch of blacklist apps)\" setting is not set up with a list of unapproved core and preinstalled applications, this is a finding.",
"description": "Applications from various sources (including the vendor, the carrier, and Google) are preinstalled on the device at the time of manufacture. Some of the applications can compromise DoD data or upload user's information to non-DoD approved servers. A user must be blocked from using such applications that exhibit behavior that can result in compromise of DoD data or DoD user information. The site administrator must analyze all pre-installed applications on the device and block all applications not approved for DoD use by configuring the application disable list.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64215r1_fix",
"fixtext": "Configure the mobile device to disable the unapproved core and preinstalled applications.\n\nOn the MDM Administration Console, set up a list of unapproved core and preinstalled applications in \"Application Blacklist (prevent launch of blacklist apps)\".",
"iacontrols": null,
"id": "V-58831",
"ruleID": "SV-73261r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to enforce an application launching policy through an application blacklist specifying a set of disallowed applications: disable unapproved core and preinstalled applications.",
"version": "LGA5-20-002101"
},
"V-58833": {
"checkid": "C-59677r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the list of unapproved core and preinstalled applications in the \"Application Blacklist (prevent launch of blacklist apps)\" setting in the MDM console.\n2. Verify the LGDMSclient package is on the list.\n\nOn the LG Android device:\n1. Unlock the device\n2. Open the device settings.\n3. Navigate to the System updates setting: Settings >> System updates \n4. Verify the System updates menu is not running and the following message is displayed: \nApplication is disabled by server policy.\n\nIf the LGDMSclient package setting is enabled, or the \"System updates\" setting can be launched, this is a finding.",
"description": "FOTA allows the user to download and install firmware updates over-the-air. These updates can include OS upgrades, security patches, bug fixes, new features and applications. Since the updates are controlled by the carriers, DoD will not have an opportunity to review and update policies prior to update availability to end users. Disabling FOTA will mitigate the risk of allowing users access to applications that could compromise DoD sensitive data. After reviewing the update and adjusting any necessary policies (i.e. disabling applications determined to pose risk), the administrator can re-enable FOTA.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64217r1_fix",
"fixtext": "Configure the mobile device to disable the FOTA client.\n\nOn the MDM Administration Console, set the LGDMSclient package as Application Blacklist (prevent launch of blacklist apps).",
"iacontrols": null,
"id": "V-58833",
"ruleID": "SV-73263r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to disable the capability for an operating system update to be automatically downloaded and installed on the mobile device.",
"version": "LGA5-20-002102"
},
"V-58835": {
"checkid": "C-59679r2_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Bluetooth File Transfer\" setting in the MDM console.\n2. Verify the Bluetooth File transfer (pbap, ftp, opp, sap, hdp, gatt, map), Network(pan) and HID(hid) settings for the Bluetooth Profile are disabled.\n\nOn the LG Android device:\n1. Unlock the device\n2. Open the device settings.\n3. Navigate to the Bluetooth setting: Settings >> Bluetooth\n4. Pair with the other device.\n5. Try to send files (for example, a photo) to paired device.\n6. Verify sending files failed and the following message is displayed: \nBluetooth is disabled by server policy.\n\nIf the Bluetooth File transfer(pbap, ftp, opp, sap, hdp, gatt, map), Network (pan) and HID(hid) profiles are not disabled in the \"Allow Bluetooth Profiles\" setting, or if the user is able to send data files via these Bluetooth profiles on the device, this is a finding.",
"description": "Unsecure Bluetooth profiles may allow either unauthenticated connections to mobile devices or transfer of sensitive DoD data without required DoD information assurance (IA) controls. Only the HSP and HFP profiles are required to meet current DoD Bluetooth needs and DoD data and voice IA controls.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64219r1_fix",
"fixtext": "Configure the mobile device to disable Bluetooth Profiles.\n\nOn the MDM Administration Console, set the \"Allow Bluetooth Profile\" to disable File transfer, Network, and HID Profiles.",
"iacontrols": null,
"id": "V-58835",
"ruleID": "SV-73265r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management setting: disable all Bluetooth profiles except for HSP (Headset Profile) and HFP (Hands-Free Profile).",
"version": "LGA5-20-002200"
},
"V-58837": {
"checkid": "C-59681r1_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console:\n1. Ask the MDM administrator to display the \"Allow Download mode\" setting in the MDM console.\n2. Verify the setting for the Download mode is disabled.\n\nOn the LG Android device:\n1. Power on the device and connect USB.\n2. Try to flash device firmware.\n3. Verify flashing device firmware is disabled and the following message is displayed: \nDownload mode is disabled by server policy.\n\nIf the \"Allow download mode\" setting is enabled, or if the user is able to flash device firmware on the device, this is a finding.",
"description": "Download mode allows the firmware of the device to be flashed (updated) by the user. All updates should be controlled by the system administrator to ensure configuration control of the security baseline of the device.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64221r1_fix",
"fixtext": "Configure the mobile device to disable download mode.\n\nOn the MDM Administration Console, set the \"Allow download mode\".",
"iacontrols": null,
"id": "V-58837",
"ruleID": "SV-73267r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to disable download mode.",
"version": "LGA5-20-002300"
},
"V-58839": {
"checkid": "C-59685r2_chk",
"checktext": "This validation procedure is performed on the LG Android device.\n\nOn the LG Android device:\n1. Open the application list and verify the presence of an MDM agent.\n2. Open the MDM agent and verify that the MDM agent has been enrolled: Settings >> Security >> Phone Administrator. MDM Agent must be checked.\n\nNote: Verification of the MDM agent is MDM vendor specific.\n\nIf the MDM agent is not present on the LG Android device, or if the MDM agent has not been enrolled (checked), this is a finding.",
"description": "Security-related parameters are those parameters impacting the security state of the system and include parameters related to the implementation of other IA controls. If these controls are not implemented, the system may be vulnerable to a variety of attacks. The use of an MDM allows an organization to assign values to security-related parameters across all the devices it manages. This provides assurance that the required mobile OS security controls are being enforced and that the device user or an adversary has not modified or disabled the controls. It also greatly increases efficiency and manageability of devices in a large-scale environment relative to an environment in which each device must be configured separately.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64223r1_fix",
"fixtext": "Enroll the device in MDM.\n\nInstall the MDM agent on the device to centrally manage configuration settings on the device.",
"iacontrols": null,
"id": "V-58839",
"ruleID": "SV-73269r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be managed by an MDM.",
"version": "LGA5-20-002500"
},
"V-58841": {
"checkid": "C-59687r1_chk",
"checktext": "This validation procedure is performed on the MDM Administration Console only.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"CC Mode\" setting in the MDM console.\n2. Verify the setting for the CC mode is set and the device is enrolled on the MDM.\n\nIf the \"Set CC Mode\" setting is disabled on the MDM console, this is a finding.",
"description": "CC mode implements several security controls required by the Mobile Device Functional Protection Profile (MDFPP). If CC mode is not implemented, DoD data is more at risk of being compromised, and the MD is more at risk of being compromised if lost or stolen.\n\nCC mode implements the following controls:\n1. Certificate Validation\nLG provides Certificate validation feature for all certificates to protect your secure connection from spoofing and invalid certificates. This capability can be automatically configured by enabling CC Mode. \n\n2. Firmware Update Protection\nExcept secure update verified by RSA (2048bit) algorithm and SHA256 for hash, unsecured firmware update methods is restricted in CC mode. \n\n3. Self-test for crypto libraries\nIf the CC Mode is enabled, self-tests for crypto libraries are automatically started at bootup time. \n\n4. Restriction of TLS cipher suites\nLimited cipher suites can be selectable in the CC mode.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64225r1_fix",
"fixtext": "Configure the mobile device to enable CC Mode.\n\nOn the MDM Administration Console, set the \"CC Mode\".",
"iacontrols": null,
"id": "V-58841",
"ruleID": "SV-73271r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to enable CC Mode.",
"version": "LGA5-20-002600"
},
"V-58843": {
"checkid": "C-59689r1_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow System Time Changes\" check box. \n2. Verify the setting is disabled. \n\nOn the LG Android device:\n1. Open the device settings.\n2. Select \"Date and time\".\n3. Verify the \"Auto date and time\" check box is checked.\n4. Verify a user cannot deselect the \"Auto date and time\" check box.\n\nIf either the \"Allow System Time Changes\" is not disabled in the MDM administration console; or the \"Auto date and time\" check box is not selected on the device; or if it is possible to deselect this option on the device, this is a finding.",
"description": "Determining the correct time a particular application event occurred on a system is critical when conducting forensic analysis and investigating system events. \n\nPeriodically synchronizing internal clocks with an authoritative time source is needed in order to correctly correlate the timing of events that occur across the enterprise. The three authoritative time sources for mobile operating systems are an authoritative time server that is synchronized with redundant United States Naval Observatory (USNO) time servers as designated for the appropriate DoD network (NIPRNet or SIPRNet), or the Global Positioning System (GPS), or the wireless carrier.\n\nTime stamps generated by the audit system in mobile operating systems shall include both date and time. The time may be expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC.\n\nSFR ID: FMT_SMF.1.1 #42",
"fixid": "F-64227r1_fix",
"fixtext": "On the MDM Console, disable \"Allow System Time Changes\".",
"iacontrols": null,
"id": "V-58843",
"ruleID": "SV-73273r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management setting: disable Allow System Time Changes.",
"version": "LGA5-20-002700"
},
"V-58845": {
"checkid": "C-59691r2_chk",
"checktext": "Note: This requirement is Not Applicable if the site has not configured the optional \"Set Owner Info\" configuration setting.\n\nThis validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Disallow Owner Info\" setting in the MDM console.\n2. Verify the setting is enabled.\n\nOn the LG Android platform device:\n1. Go to lock screen.\n2. Show owner info on the lock screen.\n3. Navigate to the password entry screen: Settings >> Lockscreen >> Contact info for lost phone\n4. Verify the Owner info is displayed but the user cannot change it.\n\nIf the \"Disallow Owner Info\" setting is not enabled, or if the user is able to change the owner info text on the device, this is a finding.",
"description": "The Owner Info screen may contain required information, including a phone number to call if a device is lost, or the DoD Warning Banner. The ability of the device user to modify the Set Owner Info screen needs to be disabled so that required info is always displayed on the locked screen.\n\nSFR ID: FMT_MOF.1.1(2) #11",
"fixid": "F-64229r1_fix",
"fixtext": "Configure the mobile device to disallow a user to change owner info displayed on the locked screen.\n\nOn the MDM Administration Console, enable the \"Disallow Owner Info\" setting.",
"iacontrols": null,
"id": "V-58845",
"ruleID": "SV-73275r1_rule",
"severity": "low",
"title": "The LG Android 5.0 platform must not allow the user to modify Owner Info on the device screen.",
"version": "LGA5-20-002800"
},
"V-58847": {
"checkid": "C-59693r3_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the \"Allow Smart Lock\" setting in the MDM console .\n2. Verify \"Allow Smart Lock\" is disabled.\n\nOn the LG Android device :\n1. Unlock the device.\n2. Open the device settings.\n3. Navigate to the Smart Lock setting: Settings > Lock Screen > click \"Smart Lock\"\n4. Verify Smart Lock is disabled and the following message is displayed: \n(Disabled by administrator)\n\nIf the Smart Lock setting is not disabled, or if the user is able to enable Smart Lock, this is a finding.",
"description": "Android Smart Lock provides the capability for the user to unlock the device using non-approved methods, including having a \"trusted\" device nearby, trusted face viewing the screen, or by swiping the device with a specific pattern. Alternate device authentication methods to using the device unlock password have not been approved for use in the DoD.\n\nSFR ID: FMT_MOF.1.1(2) #13",
"fixid": "F-64231r2_fix",
"fixtext": "Configure the mobile device to disable the Smart Lock setting.\n\nOn the MDM Administration Console, disable the \"Allow Smart Lock\" setting.",
"iacontrols": null,
"id": "V-58847",
"ruleID": "SV-73277r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must disable Android Smart Lock.",
"version": "LGA5-20-002900"
},
"V-58849": {
"checkid": "C-59695r1_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the list of unapproved core and preinstalled applications in the \"Application Blacklist (prevent launch of blacklist apps)\" setting in the MDM console.\n2. Verify the list contains LGbrowser (AT&T) and Chrome (AT&T and Verizon). \n\nOn the LG Android device:\n1. Attempt to launch the native Android Browser (LG Browser) and Chrome apps on the device.\n2. Verify the apps will not run and the following message is displayed: Application is disabled by server policy. \n\nIf the \"Allow Application Blacklist (prevent launch of blacklist apps)\" setting is not set up with \"LGbrowser\" and \"Chrome\" or the native Android browser and Chrome browser can be launched on the device, this is a finding.",
"description": "The native browser includes encryption modules that are not FIPS 140-2 validated. DoD policy requires all encryption modules used in DoD IT systems be FIPS 140-2 validated.\n\nSFR ID: FMT_MOF.1.1(2) #13",
"fixid": "F-64233r1_fix",
"fixtext": "Configure the mobile device to disable non-FIPS-validated browsers.\n\nOn the MDM Administration Console, list \"LGbrowser\" (AT&T) and \"Chrome (AT&T and Verizon) in \"Application Blacklist (prevent launch of blacklist apps)\".",
"iacontrols": null,
"id": "V-58849",
"ruleID": "SV-73279r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management setting: Disable native Android browser.",
"version": "LGA5-20-003000"
},
"V-58851": {
"checkid": "C-59697r1_chk",
"checktext": "This validation procedure is performed on both the MDM Administration Console and the LG Android device.\n\nCheck whether the appropriate setting is configured on the MDM Administration Console: \n1. Ask the MDM administrator to display the list of unapproved core and preinstalled applications in the \"Application Blacklist (prevent launch of blacklist apps)\" setting in the MDM console.\n2. Verify the list contains LGEmail. \n\nOn the LG Android device:\n1. Attempt to launch the native Android email client on the device.\n2. Verify the email app will not run and the following message is displayed:\nApplication is disabled by server policy. \n\nIf the \"Allow Application Blacklist (prevent launch of blacklist apps)\" setting is not set up with \"LGEmail\" or the native Android email client can be launched on the device, this is a finding.",
"description": "The native email client includes encryption modules that are not FIPS 140-2 validated. DoD policy requires all encryption modules used in DoD IT systems be FIPS 140-2 validated.\n\nSFR ID: FMT_MOF.1.1(2) #13",
"fixid": "F-64235r1_fix",
"fixtext": "Configure the mobile device to disable the native Android email client.\n\nOn the MDM Administration Console, list \"LGEmail\" in \"Application Blacklist (prevent launch of blacklist apps)\".",
"iacontrols": null,
"id": "V-58851",
"ruleID": "SV-73281r1_rule",
"severity": "medium",
"title": "The LG Android 5.0 platform must be configured to implement the management setting: Disable native Android email client.",
"version": "LGA5-20-003100"
}
},
"profiles": {
"MAC-1_Classified": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-1_Classified",
"title": "I - Mission Critical Classified"
},
"MAC-1_Public": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-1_Public",
"title": "I - Mission Critical Public"
},
"MAC-1_Sensitive": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-1_Sensitive",
"title": "I - Mission Critical Sensitive"
},
"MAC-2_Classified": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-2_Classified",
"title": "II - Mission Support Classified"
},
"MAC-2_Public": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-2_Public",
"title": "II - Mission Support Public"
},
"MAC-2_Sensitive": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-2_Sensitive",
"title": "II - Mission Support Sensitive"
},
"MAC-3_Classified": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-3_Classified",
"title": "III - Administrative Classified"
},
"MAC-3_Public": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-3_Public",
"title": "III - Administrative Public"
},
"MAC-3_Sensitive": {
"description": "",
"findings": {
"V-58769": "true",
"V-58771": "true",
"V-58773": "true",
"V-58775": "true",
"V-58777": "true",
"V-58779": "true",
"V-58781": "true",
"V-58783": "true",
"V-58785": "true",
"V-58787": "true",
"V-58789": "true",
"V-58791": "true",
"V-58795": "true",
"V-58797": "true",
"V-58799": "true",
"V-58801": "true",
"V-58803": "true",
"V-58805": "true",
"V-58807": "true",
"V-58809": "true",
"V-58815": "true",
"V-58817": "true",
"V-58819": "true",
"V-58821": "true",
"V-58823": "true",
"V-58825": "true",
"V-58827": "true",
"V-58829": "true",
"V-58831": "true",
"V-58833": "true",
"V-58835": "true",
"V-58837": "true",
"V-58839": "true",
"V-58841": "true",
"V-58843": "true",
"V-58845": "true",
"V-58847": "true",
"V-58849": "true",
"V-58851": "true"
},
"id": "MAC-3_Sensitive",
"title": "III - Administrative Sensitive"
}
},
"slug": "lg_android_5.x_interim_security_configuration_guide",
"title": "LG Android 5.x Interim Security Configuration Guide",
"version": "1"
}
}