Skip to content

Samsung Android must be configured to enable Knox CC Mode.

An XCCDF Rule

Description

<VulnDiscussion>The KPE CC Mode feature is a superset of other features and behavioral changes that are mandatory MDFPP requirements. If CC mode is not implemented the device will not be operating in the NIAP-certified compliant CC Mode of operation. CC Mode implements the following behavioral/functional changes to meet MDFPP requirements: - Download Mode is disabled and all updates will occur via FOTA only. In addition, CC Mode adds new restrictions, which are not to meet MDFPP requirements, but to offer better security above what is required: - Force password info following FOTA update for consistency. - Disable Remote unlock by FindMyMobile. - Restrict biometric attempts to 10 for better security. - Support Android CommonCriteria mode API implementation which secures BT and Wi-Fi keys. SFR ID: FMT_SMF_EXT.1.1 #47</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-231043r608683_rule
Severity
Low
References
Updated



Remediation - Manual Procedure

Configure Samsung Android to enable KPE CC Mode.

On the management tool, in the device restrictions section, set "CC mode" to "Enable".