Information
Backups to remote systems (including cloud backup) can leave data vulnerable to breach on the external systems, which often offer less protection than the Samsung Android 7 with Knox. Where the remote backup involves a cloud-based solution, the backup capability is often used to synchronize data across multiple devices. In this case, DoD devices may synchronize DoD-sensitive information to a user's personal device or other unauthorized computers that are vulnerable to breach. Disallowing remote backup mitigates this risk. Google Backup is a device wide control and, if enabled, will backup both personal and Knox data to personal Google cloud storage accounts.
SFR ID: FMT_SMF_EXT.1.1 #40
Solution
Configure the Samsung Android 7 with Knox to disable backup to remote systems (including commercial clouds).
On the MDM console, do the following: Deselect the "Allow Google Backup" checkbox in the "Android Restrictions" rule.