1.12 Ensure 'Smart Lock' is set to Disabled

Information

Disable Smart Lock.

Rationale:

Smart Lock detects device presence and its circumstances and automatically keeps it
unlocked even if the device has a screen password, pin or pattern enabled. Using Smart
Lock does not require you to manually unlock the device every time if the pre-defined
circumstances are met. As a best practice, do not set the device to get unlocked
automatically. For example, if your device gets stolen and if it is taken to a location pre-
defined in Smart Lock, it would automatically unlock. Similarly, if someone could replay
your voice, the device would automatically unlock.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Smart Lock:

1. Tap the Settings Gear Icon.
2. Tap Security & Location.
3. Tap Trust agents.
4. Toggle Smart Lock (Google) to Off position.


Impact:

The device would need to be manually unlocked everytime.

Default Value:

By default, Smart Lock is enabled.

See Also

https://workbench.cisecurity.org/files/2076