II - Mission Support Sensitive
Rules and Groups employed by this XCCDF Profile
-
PP-MDF-333320
Group -
Samsung Android must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile).
Some Bluetooth profiles provide the capability for remote transfer of sensitive DOD data without encryption or otherwise do not meet DOD IT security policies; therefore, must be disabled. SFRID: F...Rule Low Severity -
PP-MDF-333330
Group -
Samsung Android must be configured to disable ad hoc wireless client-to-client connection capability.
Ad hoc wireless client-to-client connections allow mobile devices to communicate with each other directly, circumventing network security policies and making the traffic invisible. This could allow...Rule Medium Severity -
PP-MDF-333350
Group -
Samsung Android's Work environment must allow only the Administrator (management tool) to perform the following management function: Install/remove DOD root and intermediate PKI certificates.
DOD root and intermediate PKI certificates are used to verify the authenticity of PKI certificates of users and web services. If the user is allowed to remove root and intermediate certificates, th...Rule Medium Severity -
PP-MDF-993300
Group -
Samsung Android must be enrolled as a COPE device.
The Work profile is the designated application group for the COPE use case. SFRID: FMT_MOF_EXT.1.2 #47Rule Medium Severity -
PP-MDF-993300
Group -
Samsung Android must be configured to disallow configuration of the device's date and time.
Determining the correct time a particular application event occurred on a system is critical when conducting forensic analysis and investigating system events. Periodically synchronizing internal...Rule Medium Severity -
PP-MDF-993300
Group -
Samsung Android's Work profile must have the DOD root and intermediate PKI certificates installed.
DOD root and intermediate PKI certificates are used to verify the authenticity of PKI certificates of users and web services. If the root and intermediate certificates are not available, an adversa...Rule Medium Severity -
PP-MDF-993300
Group -
Samsung Android's Work environment must be configured to enable audit logging.
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify attacks so that breaches can either be prevented or limited in their scope....Rule Medium Severity -
PP-MDF-993300
Group -
Samsung Android's Work environment must be configured to prevent users from adding personal email accounts to the work email app.
If the user is able to add a personal email account (POP3, IMAP, EAS) to the work email app, it could be used to forward sensitive DOD data to unauthorized recipients. Restricting email account add...Rule Medium Severity -
PP-MDF-993300
Group -
Samsung Android's Work profile must be configured to enable Common Criteria (CC) mode.
The CC mode feature is a superset of other features and behavioral changes that are mandatory MDFPP requirements. If CC mode is not implemented, the device will not be operating in the NIAP-certifi...Rule Low Severity -
PP-MDF-993300
Group -
Samsung Android device users must complete required training.
The security posture of Samsung devices requires the device user to configure several required policy rules on their device. User-Based Enforcement (UBE) is required for these controls. In addition...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.