Rule ID
SV-277005r1192665_rule
Version
V2R4
CCIs
CCI-000366
This feature must be disabled to comply with DOD electronic records retention requirements for mobile devices. Otherwise, mobile device users could wipe the device, which would violate DOD policy. SFR ID: FMT_MOF_EXT.1.2 #47
Verify, the Samsung device user has been trained to not perform a factory wipe without the approval of the authorizing official (AO). Conform by reviewing site mobile device training records or the User Agreement. This is a User-Based Enforcement (UBE) control. If the Samsung device user has not been trained to not perform a factory wipe without the approval of the AO, this is a finding.
Train users to not perform a factory reset on the Samsung device without AO approval. Document training via the site's mobile device training records or the User Agreement. This is a UBE control. Note: It is not possible for the MDM to enforce this control when the Samsung device is deployed in COPE mode.