1.12 Ensure 'Smart Lock' is set to 'Disabled'

Information

Disable Smart Lock.
The recommended state for this setting is: Disabled.

Rationale:

Smart Lock detects device presence and its circumstances and automatically keeps it unlocked even if the device has a screen password, pin or pattern enabled. Using Smart Lock does not require you to manually unlock the device every time if the pre-defined circumstances are met. As a best practice, do not set the device to get unlocked automatically. For example, if your device gets stolen and if it is taken to a location pre-defined in Smart Lock, it would automatically unlock. Similarly, if someone could replay your voice, the device would automatically unlock.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Smart Lock:

Tap the Settings Gear Icon.
Tap Security.
Tap Advanced.
Tap Trust agents..
Toggle Smart Lock (Google) to OFF position.

Impact:

The device would need to be manually unlocked every time.
Default Value:
By default, Smart Lock is enabled.

See Also

https://workbench.cisecurity.org/files/2466

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|16.5

Plugin: MDM

Control ID: dec226ecb3838d311b17a72e87ffd8995b52c3c42192a3cd6c09c1396a5696f7