STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Google Android 15 COBO Security Technical Implementation Guide

V-267449

CAT III (Low)

Google Android 15 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile).

Rule ID

SV-267449r1031532_rule

STIG

Google Android 15 COBO Security Technical Implementation Guide

Version

V1R4

CCIs

CCI-000381, CCI-001761

Discussion

Some Bluetooth profiles provide the capability for remote transfer of sensitive DOD data without encryption or otherwise do not meet DOD IT security policies and therefore must be disabled. SFRID: FMT_SMF_EXT.1.1/BLUETOOTH BT-8

Check Content

Determine if the authorizing official (AO) has approved the use of Bluetooth at the site.

If the AO has not approved the use of Bluetooth, verify Bluetooth has been disabled.

On the EMM console:

COBO:

1. Open "User restrictions" section.
2. Verify "Disallow Bluetooth" is toggled to "ON".

COPE:

1. Open "User restrictions on parent" section.
2. Verify "Disallow Bluetooth" is toggled to "ON".

On the managed Google Android 15 device:

COBO and COPE:

1. Go to Settings >> Connected Devices >> Connection Preferences >> Bluetooth.
2. Verify "Use Bluetooth" is set to OFF and cannot be toggled to "ON".

If the AO has approved the use of Bluetooth, on the managed Android 15 device:

1. Go to Settings >> Connected Devices.
2. Verify only approved Bluetooth connected devices using approved profiles are listed.

If the AO has not approved the use of Bluetooth, and Bluetooth use is not disabled via an EMM-managed device policy, this is a finding.

If the AO has approved the use of Bluetooth, and Bluetooth devices using unauthorized Bluetooth profiles are listed on the device under "Connected devices", this is a finding.

Fix Text

Configure the Google Android 15 device to disable Bluetooth or if the AO has approved the use of Bluetooth (for example, for car hands-free use), train the user to connect to only authorized Bluetooth devices using only HSP, HFP, or SPP Bluetooth capable devices (UBE).

To disable Bluetooth use the following procedure:

On the EMM console:

COBO:

1. Open "User restrictions" section.
2. Toggle "Disallow Bluetooth" to "ON".

COPE:

1. Open "User restrictions on parent" section.
2. Toggle "Disallow Bluetooth" to "ON".

The user training requirement is satisfied in requirement GOOG-15-009800.