KNOX-07-018900 - The Samsung Android 7 with Knox must use a NIAP certified container for work data and applications.

Information

When a DoD mobile device contains apps in the personal container that have not been vetted by the DoD for malware or risky behaviors, the personal container must be considered an untrusted environment. Therefore the data separation implementation between the personal data container and the work container must meet the requirements of Mobile Device Fundamentals Protection Profile (FDP_ACF_EXT.1.2) to insure sensitive DoD data in the work container is adequately separated.

SFR ID: FMT_SMF_EXT.1.1 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Deploy DoD Samsung mobile devices with the Knox container and implement the Knox container. (See requirement KNOX-07-012800.)

Note: Samsung Knox is currently the only container technology/application that is NIAP certified for Samsung mobile devices.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Samsung_Android_OS_7_with_Knox_2-x_V1R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-91321r1_rule, STIG-ID|KNOX-07-018900, Vuln-ID|V-76625

Plugin: MDM

Control ID: e5608cdb4aa82bfeaa57f2d5e489deb8536d2d1b41866a2c11da6ce1b3a3442d