STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Google Android 15 COBO Security Technical Implementation Guide

V-267438

CAT II (Medium)

Google Android 15 allow list must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini.

Rule ID

SV-267438r1042520_rule

STIG

Google Android 15 COBO Security Technical Implementation Guide

Version

V1R4

CCIs

CCI-000803

Discussion

Sensitive DOD data could be exposed when an AI app processes device data in the cloud. SFRID: FMT_SMF.1.1 #8

Check Content

Review managed Google Android 15 device configuration settings to determine if the mobile device has an AI application that processes device data in the cloud, including Google Gemini.

This validation procedure is performed only on the EMM Administration Console.

On the EMM console:

1. Review the list of selected Managed Google Play apps.
2. Verify no AI applications that process device data in the cloud, including Google Gemini, are included.

If the EMM console device policy includes AI applications that process device data in the cloud, including Google Gemini, this is a finding.

Note: This restriction does not include Gemini Nano. Gemini Nano is a built-in capability of Android 15 and processes device data on the device. Refer to Section 2, Artificial Intelligence Restrictions, of the STIG Supplemental document for more information.

Fix Text

Configure the Google Android 15 device application allow list to exclude AI applications that process device data in the cloud, including Google Gemini.

Note: This restriction does not include Gemini Nano. Gemini Nano is a built-in capability of Android 15 and processes device data on the device. See Section 2 "Artificial Intelligence Restrictions" of the STIG Supplemental document for more information.