GOOG-14-701100 - Google Android 14 must prohibit DOD VPN profiles in the Personal Profile.

Information

If DOD VPN profiles are configured in the Personal Profile DOD sensitive data world be at risk of compromise and the DOD network could be at risk of being attacked by malware installed on the device.

SFR ID: FMT_SMF_EXT.1.1 #3

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Do not configure DOD VPN profiles in the Personal Profile. If there is a DOD VPN profile configured in the Personal Profile, remove it.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_14_BYOAD_Y24M03_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6(1), 800-53|CM-6b., CAT|II, CCI|CCI-000366, CCI|CCI-000370, Rule-ID|SV-260082r948451_rule, STIG-ID|GOOG-14-701100, Vuln-ID|V-260082

Plugin: MDM

Control ID: 61ec393477dc1a7b88b722d2267115064036b5c9511fd796a6146235426d7ca9