Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-251826 | KNOX-12-110240 | SV-251826r814234_rule | Medium |
Description |
---|
Backups to remote systems (including cloud backup) can leave data vulnerable to breach on the external systems, which often offer less protection than the MOS. Where the remote backup involves a cloud-based solution, the backup capability is often used to synchronize data across multiple devices. In this case, DoD devices may synchronize DoD sensitive information to a user's personal device or other unauthorized computers that are vulnerable to breach. Disallowing remote backup mitigates this risk. SFR ID: FMT_SMF_EXT.1.1 #40 |
STIG | Date |
---|---|
Samsung Android 12 with Knox 3.x COBO Security Technical Implementation Guide | 2022-06-07 |
Check Text ( C-55286r814232_chk ) |
---|
Verify requirement KNOX-12-110230 (Disallow modify accounts) has been implemented. If "Disallow modify accounts" has not been implemented, this is a finding. |
Fix Text (F-55240r814233_fix) |
---|
Implement "Disallow modify accounts" (see requirement KNOX-12-110230). |