Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-56097 | KNOX-35-022700 | SV-70351r1_rule | Medium |
Description |
---|
Text messages can potentially include sensitive information. When this feature is enabled, both text message data and the sender's name or number will be displayed on the lock screen. This may result in an adversary obtaining potentially sensitive data even when the device is in a locked state. Disabling this feature will mitigate this risk. SFR ID: FMT_SMF.1.1 #42 |
STIG | Date |
---|---|
Samsung Android (with Knox 2.x) STIG | 2016-02-25 |
Check Text ( C-56667r1_chk ) |
---|
This validation procedure is performed on the Samsung Knox for Android device. On the Samsung Knox for Android device: 1. Open the Samsung native messaging application. 2. Select settings. 3. Select "Notifications". 4. Verify "Lock screen" setting under Preview Message is disabled. If "Lock screen" setting is enabled and cannot be disabled, this is a finding. (Note: This setting cannot be managed by the MDM administrator and is a User Based Enforcement (UBE) requirement.) |
Fix Text (F-60975r1_fix) |
---|
Configure the mobile operating system to disable preview of messages in the lock screen. |