UCF STIG Viewer Logo

LG Android 6.x Security Technical Implementation Guide


Overview

Date Finding Count (46)
2019-02-21 CAT I (High): 5 CAT II (Med): 32 CAT III (Low): 9
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC III - Administrative Sensitive)

Finding ID Severity Title
V-91783 High Only authorized versions of the LG Android OS must be used.
V-66885 High LG Android 6.x must implement the management setting: Enable CC mode.
V-66805 High LG Android 6.x must require a valid password be successfully entered before the mobile device data is unencrypted.
V-66823 High LG Android 6.x must protect data at rest on built-in storage media.
V-66825 High LG Android 6.x must protect data at rest on removable storage media.
V-66899 Medium LG Android 6.x must implement the management setting: list approved apps on the Whitelisted Android Apps (for Work Profile). This requirement is only valid for activation type COPE#2.
V-66895 Medium LG Android 6.x must be configured to disable download mode.
V-66897 Medium LG Android 6.x must implement the management setting: Disallow addition of Google Accounts (for Work Profile). This requirement is only valid for activation type COPE#2.
V-66891 Medium LG Android 6.x must not allow Google Auto sync.
V-66893 Medium LG Android 6.x must be configured to implement the management settings: Disable Android Beam.
V-66869 Medium LG Android 6.x must disable authentication mechanisms providing user access to protected data other than a Password Authentication Factor: Disable Smart Lock.
V-66815 Medium LG Android 6.x must enforce an application installation policy by specifying one or more authorized application repositories by disabling Google Play.
V-66817 Medium LG Android 6.x must enforce an application installation policy by specifying an application whitelist.
V-66819 Medium LG Android 6.x must not display notifications when the device is locked.
V-66843 Medium LG Android 6.x must be configured to implement the management setting: Disable Bluetooth Data Transfer.
V-66873 Medium LG Android 6.x must implement the management setting: Disable USB host storage.
V-66871 Medium LG Android 6.x must not allow protocols supporting wireless remote access connections: USB tethering.
V-66833 Medium LG Android 6.x must not allow backup to remote systems.
V-66831 Medium LG Android 6.x must not allow backup to locally connected systems.
V-66837 Medium LG Android 6.x must disable authentication mechanisms providing user access to protected data other than a Password Authentication Factor: Disable fingerprint.
V-66879 Medium LG Android 6.x must implement the management setting: Disable Nearby devices.
V-66889 Medium LG Android 6.x must be configured to implement the management setting: Disable LG browser and Chrome browser. Note: This requirement is Not Applicable for the COPE#2 activation type.
V-66829 Medium LG Android 6.x must not allow a USB mass storage mode.
V-66883 Medium LG Android 6.x must implement the management setting: Disable System Time Changes.
V-66881 Medium LG Android 6.x must implement the management setting: Disable Removal of device administrator rights.
V-66887 Medium LG Android 6.x must implement the management setting: Disable all non-approved preinstalled applications.
V-66809 Medium LG Android 6.x must lock the display after 15 minutes (or less) of inactivity.
V-66865 Medium LG Android 6.x must enforce an application installation policy by specifying one or more authorized application repositories by disabling unknown sources.
V-66867 Medium LG Android 6.x must not allow protocols supporting wireless remote access connections: Bluetooth tethering.
V-66861 Medium LG Android 6.x must be configured to disable automatic updates of system software.
V-66863 Medium LG Android 6.x must implement the management setting: Install CA certificate.
V-66903 Medium LG Android 6.x must implement the management setting: Install CA certificate (for Work Profile). This requirement is only valid for activation type COPE#2.
V-66821 Medium LG Android 6.x must not allow use of developer modes.
V-66907 Medium LG Android 6.x must implement the management setting: Disable allow copy and paste between Work Profile and personal space. This requirement is only valid for activation type COPE#2.
V-66905 Medium LG Android 6.x must implement the management setting: Disable content sharing (for Work Profile). This requirement is only valid for activation type COPE#2.
V-66841 Medium LG Android 6.x whitelist must not include applications with the following characteristics: -backup MD data to non-DoD cloud servers (including user and application access to cloud backup services); -transmit MD diagnostic data to non-DoD servers; -voice assistant application if available when MD is locked; -voice dialing application if available when MD is locked; -allows synchronization of data or applications between devices associated with user; -payment processing; and -allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs, display screens (screen mirroring), or printers.
V-66845 Medium LG Android 6.x must be configured to disable VPN split-tunneling.
V-66875 Low LG Android 6.x must implement the management setting: Disable Voice Command.
V-66811 Low LG Android 6.x must not allow passwords that include more than two repeating or sequential characters.
V-66835 Low LG Android 6.x must disable automatic transfer of diagnostic data to an external device other than an MDM service with which the device has enrolled.
V-66813 Low LG Android 6.x must not allow more than 10 consecutive failed authentication attempts.
V-66827 Low LG Android 6.x must display the DoD advisory warning message at start-up or each time the user unlocks the device.
V-66877 Low LG Android 6.x must implement the management setting: Disable NFC.
V-66839 Low LG Android 6.x must enable VPN protection.
V-66807 Low LG Android 6.x must enforce a minimum password length of 6 characters.
V-66901 Low LG Android 6.x must implement the management setting: Set uninstall not allowed for mandatory Work Profile apps. This requirement is only valid for activation type COPE#2.