STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Google Android 15 COPE Security Technical Implementation Guide

V-278367

CAT II (Medium)

The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps.

Rule ID

SV-278367r1134580_rule

STIG

Google Android 15 COPE Security Technical Implementation Guide

Version

V1R4

CCIs

CCI-000366

Discussion

Wi-Fi Aware allows direct connections between nearby devices for fast data transfer, video streaming, and multiplayer gaming. It allows full peer-to-peer device discovery and communication where two or more devices are publishing and/or subscribing to the same known service name. There is risk that sensitive DOD information could be transferred from a DOD mobile device to a non-DOD device or from Work Profile apps on a DOD device to Personal Profile apps on a non-DOD device.

Check Content

Review device configuration settings to confirm Wi-Fi Aware is disabled for each work profile app. 
 
This procedure is performed on the EMM console.
 
For each Work Profile app, verify the app is configured to deny the NEARBY_WIFI_DEVICE permission. Note: Not all apps will support Wi-Fi Aware and have the NEARBY_WIFI_DEVICE permission.

If on the EMM console the NEARBY_WIFI_DEVICE permission is not set to "deny" for all Work Profile apps that support Wi-Fi Aware, this is a finding.

Fix Text

Configure the Google Android device to disable Wi-Fi Aware for all Work Profile apps.
 
On the EMM console:

For each Work Profile app, configure the NEARBY_WIFI_DEVICE permission to "deny" to block the use of Wi-Fi Aware if the app supports this feature. If the app does not support Wi-Fi Aware, a NEARBY_WIFI_DEVICE permission may not be available.