Skip to content

Samsung Android Personal Environment must be configured to enforce the system application disable list.

An XCCDF Rule

Description

The system application disable list controls user access/execution of all core and pre-installed applications. Core application: Any application integrated into Samsung Android by Google or Samsung. Pre-installed application: Additional non-core applications included in the Samsung Android build by Google, Samsung, or the wireless carrier. Some system applications can compromise DoD data or upload users' information to non-DoD-approved servers. A user must be blocked from using applications that exhibit behavior that can result in compromise of DoD data or DoD user information. The site Administrator must analyze all pre-installed applications on the device and disable all applications not approved for DoD use by configuring the system application disable list. SFR ID: FMT_SMF_EXT.1.1 #47

ID
SV-231038r608683_rule
Version
KNOX-11-017800
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the Samsung Android device to enforce the system application disable list.

This guidance is only for the Personal Environment of a COPE deployment.

On the management tool, in the device application section, add all non-AO-approved system app packages to the "system app disable list".