1.25 Ensure 'Guest profiles' do not exist

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Do not add any guest profiles on the device.

Rationale:

Users and the guest profile can do most of the same things as the device's owner, but each
profile has its own storage space. Guests could install malicious apps or carry out any other
malicious activities that may compromise overall device security. Also, Wi-Fi and Bluetooth
connections are shared which could give guests unauthorized access to networks/devices
that could compromise data. Hence, do not add any guest profiles on the device.

If you need to give your device to someone for temporary use, use Screen Pinning to
restrict access to the desired app and be in the complete visibility of your device all the
time.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps remove the Guest profile:

1. Open Quick Settings drawer.
2. Tap the Profile icon.
3. Switch to Guest profile.
4. Open Quick Settings drawer.
5. Tap Remove guest.
6. Confirm removal by tapping remove.

Impact:

None

Default Value:

By default, Guest profiles do not exist.

See Also

https://workbench.cisecurity.org/files/2076