Samsung Android must be configured to disable authentication mechanisms providing user access to protected data other than a Password Authentication Factor: Face recognition.
An XCCDF Rule
Description
The biometric factor can be used to authenticate the user to unlock the mobile device. Unapproved/evaluated biometric mechanisms could allow unauthorized users to have access to DOD sensitive data if compromised. By not permitting the use of unapproved/evaluated biometric authentication mechanisms, this risk is mitigated. SFR ID: FMT_SMF_EXT.1.1 #22, FIA_UAU.5.1
- ID
- SV-258633r1015814_rule
- Version
- KNOX-14-110080
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the Samsung Android devices to disable face recognition.
On the management tool, in the device restrictions, set "Face recognition" to "Disable".