2.2 Ensure 'Location Services' is set to Disabled

Information

Disable Location Services when not in use.

Rationale:

Location Services allows applications such as Maps and Internet websites to gather and use
data indicating the user's location. The user's location is determined using available
information from cellular network data, local Wi-Fi networks, Bluetooth and GPS. If the
user turns off Location Services, the user will be prompted to turn it back on again the next
time any application tries to use this feature.

Disabling location services reduces the capability of an attacker to determine or track the
user's location via websites, locally installed applications or other means without user's
consent. Thus, it should be disabled when not in use.

Note: Location service is very important for tracking your lost device if the device data is
not disabled. Make a judicious call and decide what works best for you or in your
environment.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Location Services:

1. Tap Settings Gear Icon.
2. Tap Security & Location.
3. Scroll to Privacy.
4. Tap Location.
5. Toggle to the Off position.

Impact:

Each time an application needs location data, the user activity would be interrupted to
enable the location services.

Another impact could be on finding your lost device. If the device is lost and the location
services are disabled, you cannot use remote locate services such as Android Device
Manager.

Default Value:

By default, Location Services is enabled.

See Also

https://workbench.cisecurity.org/files/2076