UCF STIG Viewer Logo

The Samsung Knox for Android platform must be configured to implement the management setting: disable Insecure VPN Connections.


Overview

Finding ID Version Rule ID IA Controls Severity
V-56065 KNOX-35-020400 SV-70319r1_rule Medium
Description
Without strong mutual authentication, a mobile device may connect to an unauthorized network. In many cases, the user may falsely believe that the device is connected to an authorized network and then provide authentication credentials and other sensitive information. A strong bidirectional, cryptographically based authentication method mitigates this risk. SFR ID: FMT_SMF.1.1 #42
STIG Date
Samsung Android (with Knox 2.x) STIG 2016-02-25

Details

Check Text ( C-56635r1_chk )
This validation procedure is performed on the MDM Administrative Console.

Check whether the appropriate setting is configured on the MDM Administration Console:
1. Ask the MDM administrator to display the "Disable Insecure VPN Connections" check box in the "Android Restrictions" rule.
2. Verify the check box is selected.

If the "Disable Insecure VPN Connections" check box is not selected, this is a finding.
Fix Text (F-60943r1_fix)
Configure the operating system to authenticate devices before establishing remote connections.

On the MDM Console, select the "Disable Insecure VPN Connections" check box in the "Android Restrictions" rule.