UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Samsung Android must be configured to lock the display after 15 minutes (or less) of inactivity.


Overview

Finding ID Version Rule ID IA Controls Severity
V-260444 KNOX-14-710070 SV-260444r950911_rule Medium
Description
The screen lock timeout must be set to a value that helps protect the device from unauthorized access. Having a too-long timeout would increase the window of opportunity for adversaries who gain physical access to the mobile device through loss, theft, etc. Such devices are much more likely to be in an unlocked state when acquired by an adversary, thus granting immediate access to the data on the mobile device. The maximum timeout period of 15 minutes has been selected to balance functionality and security; shorter timeout periods may be appropriate depending on the risks posed to the mobile device. Satisfies: PP-MDF-333026,PP-MDF-333030 SFR ID: FMT_SMF_EXT.1.1 #2a, 2bb
STIG Date
Samsung Android 14 MDFPP 3.3 BYOAD Security Technical Implementation Guide 2024-02-21

Details

Check Text ( C-64174r950909_chk )
Review the configuration to determine if the Samsung Android devices' Work Environment is locking the device display after 15 minutes (or less) of inactivity.

This validation procedure is performed on both the management tool and the Samsung Android device.

On the management tool, in the Work environment password policies, verify "max time to screen lock" is set to "15 minutes" or less.

On the Samsung Android device, confirm if the user has "One Lock" enabled (Settings >> Security and privacy >> More security settings >> Work profile security >> Use one lock).

If "One Lock" is enabled:
1. Open Settings >> Lock screen.
2. Verify "Secure lock settings" is present and tap it.
3. Enter current password.
4. Tap "Auto lock when screen turns off".
5. Verify the listed timeout values are 15 minutes or less.

If "One Lock" is disabled:
1. Open Settings >> Security and privacy >> More security settings >> Work profile security >> Auto lock work profile.
2. Verify the listed timeout values are 15 minutes or less.

If on the management tool "max time to screen lock" is not set to "15 minutes" or less, or on the Samsung Android device the listed Screen timeout values include durations of more than 15 minutes, this is a finding.
Fix Text (F-64081r950910_fix)
Configure the Samsung Android devices to lock the device display after 15 minutes (or less) of inactivity.

On the management tool, in the device password policies, set "max time to screen lock" to "15 minutes" or less.

A device password must be set for "max time to screen lock" to become active.