UCF STIG Viewer Logo

LG Android 6.x whitelist must not include applications with the following characteristics: -backup MD data to non-DoD cloud servers (including user and application access to cloud backup services); -transmit MD diagnostic data to non-DoD servers; -voice assistant application if available when MD is locked; -voice dialing application if available when MD is locked; -allows synchronization of data or applications between devices associated with user; -payment processing; and -allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs, display screens (screen mirroring), or printers.


Overview

Finding ID Version Rule ID IA Controls Severity
V-66841 LGA6-20-102601 SV-81331r2_rule Medium
Description
Requiring all authorized applications to be in an application whitelist prevents the execution of any applications (e.g., unauthorized, malicious) that are not part of the whitelist. Failure to configure an application whitelist properly could allow unauthorized and malicious applications to be downloaded, installed, and executed on the mobile device, causing a compromise of DoD data accessible by these applications. SFR ID: FMT_SMF_EXT.1.1 #10b
STIG Date
LG Android 6.x Security Technical Implementation Guide 2019-02-21

Details

Check Text ( C-67491r2_chk )
This validation procedure is performed on the MDM Administration Console.

On the MDM console, do the following:

1. Ask the MDM administrator to display the "Application blacklist configuration (launch)” setting in the "Android Application" rule.
2. Verify the list contains all pre-installed applications which have not been approved by the Authorizing Official (AO).
3. Ask the MDM administrator to display the "Application whitelist configuration (install)” setting in the "Android Application" rule.
4. Verify no applications with the following prohibited features are included on the whitelist.
-backup MD data to non-DoD cloud servers (including user and application access to cloud backup services);
-transmit MD diagnostic data to non-DoD servers;
-voice assistant application if available when MD is locked;
-voice dialing application if available when MD is locked;
-allows synchronization of data or applications between devices associated with user;
-payment processing; and
-allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs, display screens (screen mirroring), or printers.
5. Verify the policy has been assigned to all groups.

Note: Refer to the Supplemental document for additional information.

If on the MDM console the "Application blacklist configuration (launch)" does not have all unapproved pre-installed applications or the "Application whitelist configuration (install)" has applications with unauthorized features, this is a finding.
Fix Text (F-72941r2_fix)
Configure the MDM console application whitelist (install) to exclude applications with the following characteristics:

-backup MD data to non-DoD cloud servers (including user and application access to cloud backup services);
-transmit MD diagnostic data to non-DoD servers;
-voice assistant application if available when MD is locked;
-voice dialing application if available when MD is locked;
-allows synchronization of data or applications between devices associated with user;
-payment processing; and
-allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs, display screens (screen mirroring), or printers.

Configure the MDM console application blacklist (launch) to include all pre-installed applications which have not been approved by the AO.