MOTO-09-001400 - The Motorola Android Pie must be configured to disable Bluetooth or configured via User Based Enforcement (UBE) to allow Bluetooth for only HSP (Headset Profile), HFP (HandsFree Profile), or SPP (Serial Port Profile) capable devices - Serial Port Profile capable devices.

Information

Some Bluetooth profiles provide the capability for remote transfer of sensitive DoD data without encryption or otherwise do not meet DoD IT security policies and therefore must be disabled.

SFR ID: FMT_SMF_EXT.1.1 #18h

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the Motorola Android device to disable Bluetooth or, if the AO has approved the use of Bluetooth (for example, for car hands-free use), train the user to connect to only authorized Bluetooth devices using only HSP, HFP, or SPP Bluetooth capable devices (User Based Enforcement (UBE).

To disable Bluetooth, use the following procedure.

On the MDM console:
1. Open Restrictions section.
2. Toggle 'Disallow Bluetooth' to 'On'.

The user training requirement is satisfied in requirement MOTO-09-008700.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MOT_Android_9-x_Y22M10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., 800-53|CM-7(1)(b), CAT|III, CCI|CCI-000366, CCI|CCI-001761, Rule-ID|SV-230118r859729_rule, STIG-ID|MOTO-09-001400, Vuln-ID|V-230118

Plugin: MDM

Control ID: 50496f2a50df8c19c37438c698203c60315a2f2e17b61bb5575da928f3b13bb2