UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Samsung Android device users must complete required training.


Overview

Finding ID Version Rule ID IA Controls Severity
V-258654 KNOX-14-110300 SV-258654r931162_rule Medium
Description
The security posture of Samsung devices requires the user to configure several required policy rules on their device. User-Based Enforcement (UBE) is required for these controls. In addition, if the Authorizing Official (AO) has approved the use of an unmanaged personal space, the user must receive training on risks. If a user is not aware of their responsibilities and does not comply with UBE requirements, the security posture of the Samsung mobile device may become compromised, and DOD sensitive data may become compromised. SFR ID: FMT_MOF_EXT.1.2 #47
STIG Date
Samsung Android OS 14 with Knox 3.x COBO Security Technical Implementation Guide 2023-10-18

Details

Check Text ( C-62394r931160_chk )
Review a sample of site User Agreements for Samsung device users or similar training records and training course content.

Verify Samsung device users have completed required training. The intent is that required training is renewed on a periodic basis in a time period determined by the AO.

If any Samsung device user has not completed required training, this is a finding.
Fix Text (F-62303r931161_fix)
Have all Samsung device users complete training on the following topics. Users should acknowledge they have reviewed training via a signed User Agreement or similar written record.

Training topics:

- Operational security concerns introduced by unmanaged applications/unmanaged personal space, including applications using global positioning system (GPS) tracking.

- Need to ensure no DOD data is saved to the personal space or transmitted from a personal app (for example, from personal email).

- If the Purebred key management app is used, users are responsible for maintaining positive control of their credentialed device at all times. The DOD PKI certificate policy requires subscribers to maintain positive control of the devices that contain private keys and report any loss of control so that the credentials can be revoked. Upon device retirement, turn-in, or reassignment, ensure a factory data reset is performed prior to device handoff. Follow mobility service provider decommissioning procedures as applicable.

- How to configure the following UBE controls (users must configure the control) on the Samsung device:
1. Secure use of Calendar Alarm.
2. Local screen mirroring and MirrorLink procedures (authorized/not authorized for use).
3. Do not connect Samsung devices (via either DeX Station or dongle) to any DOD network via Ethernet connection.
4. Do not upload DOD contacts via smart call and caller ID services.
5. Disable Wi-Fi Sharing.
6. Do not configure a DOD network (work) VPN profile on any third-party VPN client installed in the personal space.

- AO guidance on acceptable use and restrictions, if any, on downloading and installing personal apps and data (music, photos, etc.) in the Samsung device personal space.