Skip to content

Samsung Android OS 13 with Knox 3.x COPE Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • PP-MDF-323060

    Group
  • Samsung Android's Work profile must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: Names.

    The application allowlist, in addition to controlling the installation of applications on the MD, must control user access/execution of all core and preinstalled applications, or the MD must provid...
    Rule Medium Severity
  • PP-MDF-323070

    Group
  • PP-MDF-323080

    Group
  • PP-MDF-990000

    Group
  • Samsung Android's Work profile must be configured to enable audit logging.

    Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify attacks so that breaches can either be prevented or limited in their scope....
    Rule Medium Severity
  • PP-MDF-990000

    Group
  • Samsung Android's Work profile must be configured to prevent users from adding personal email accounts to the work email app.

    If the user is able to add a personal email account (POP3, IMAP, EAS) to the work email app, it could be used to forward sensitive DOD data to unauthorized recipients. Restricting email account add...
    Rule Medium Severity
  • PP-MDF-323250

    Group
  • PP-MDF-323280

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules