GOOG-13-709800 - Google Android 13 users must complete required training.

Information

The security posture of Google devices requires the device user to configure several required policy rules on their device. User-Based Enforcement (UBE) is required for these controls. In addition, if the Authorizing Official (AO) has approved the use of an unmanaged personal space, the user must receive training on risks. If a user is not aware of their responsibilities and does not comply with UBE requirements, the security posture of the Google mobile device and DOD sensitive data may become compromised.

SFR ID: NA

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

All Google Android 13 device users must complete training on the following training topics (users must acknowledge that they have reviewed training via a signed User Agreement or similar written record):
- Operational security concerns introduced by unmanaged applications/unmanaged personal space, including applications using global positioning system (GPS) tracking.
- The need to ensure no DOD data is saved to the personal space or transmitted from a personal app (for example, from personal email).
- If the Purebred key management app is used, users are responsible for always maintaining positive control of their credentialed device. The DOD PKI certificate policy requires subscribers to maintain positive control of the devices that contain private keys and to report any loss of control so the credentials can be revoked. Upon device retirement, turn-in, or reassignment, ensure that a factory data reset is performed prior to device hand-off. Follow mobility service provider decommissioning procedures as applicable.
- How to configure the following UBE controls (users must configure the control) on the Google device:
**Do not remove DOD intermediate and root PKI digital certificates
**Do not configure a DOD network (work) VPN profile on any third-party VPN client installed in the personal space
- How to implement OneLock.
- Screenshots will not be taken of any 'work' related managed data.-Screenshots will not be taken of any 'work' related managed data.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_13_BYOAD_Y24M04_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-258488r929502_rule, STIG-ID|GOOG-13-709800, Vuln-ID|V-258488

Plugin: MDM

Control ID: 4a43103bf8e4941a5117cb5599225519eb5a3dce83b573b1cf8c81b1d5670914