STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 1 hour ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to STIGs

Samsung Android OS 17 with Knox 3.x COBO Security Technical Implementation Guide

Version

V1R1

Release Date

Aug 7, 2026

SCAP Benchmark ID

SS_Android_OS_17_KPE_3-x_COBO_STIG

Total Checks

45

Tags

mobile
CAT I: 2CAT II: 35CAT III: 8

This Security Technical Implementation Guide is published as a tool to improve the security of Department of War (DoW) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (45)

V-286294MEDIUMSamsung Android 17 must allow only the administrator (EMM) to install/remove DoW root and intermediate PKI certificates.V-286298LOWSamsung Android 17 must [DoW-restricted selection: allow the user to choose whether to accept the certificate in these cases, not accept the certificate] when it cannot establish a connection to determine the validity of a certificate.V-286308MEDIUMSamsung Android 17 must be configured to enforce a minimum password length of six characters.V-286309MEDIUMSamsung Android 17 must be configured to not allow passwords that include more than four repeating or sequential characters.V-286310MEDIUMSamsung Android 17 must be configured to lock the display after 15 minutes (or less) of inactivity.V-286311MEDIUMSamsung Android 17 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity - Disable trust agents.V-286312MEDIUMSamsung Android 17 must be configured to not allow more than 10 consecutive failed authentication attempts.V-286313MEDIUMSamsung Android 17 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DoW-approved commercial app repository, MDM server, mobile application store].V-286314MEDIUMSamsung Android 17 must be configured to enforce an application installation policy by specifying an application allow list that restricts applications by the following characteristic: names.V-286315MEDIUMThe Samsung Android 17 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DoW cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DoW servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with the user; - Payment processing; - Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers; - Backs up its own data to a remote system; and - Renders TV shows and movies.V-286316MEDIUMThe Samsung Android 17 allow list must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini.V-286317MEDIUMSamsung Android 17 must be configured to not display the following (work profile) notifications when the device is locked: All notifications.V-286319HIGHSamsung Android 17 must be configured to enable encryption for data at rest on removable storage media or, alternately, the use of removable storage media must be disabled.V-286320MEDIUMSamsung Android 17 must be configured to disable authentication mechanisms providing user access to protected data other than a password authentication factor: Face authentication factor (unless NIAP-validated).V-286323MEDIUMSamsung Android 17 must be configured to disable developer modes.V-286325MEDIUMThe Samsung Android 17 work profile must be configured to enable audit logging.V-286327LOWSamsung Android 17 must be configured to display the DoW advisory warning message at startup or each time the user unlocks the device.V-286329MEDIUMSamsung Android 17 must be configured to disable USB mass storage mode.V-286330MEDIUMSamsung Android 17 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.V-286331MEDIUMSamsung Android 17 must be configured to not allow backup of [all applications, configuration data] to remote systems. (This requirement applies to the work profile for COPE.) - Disable Data Sync Framework.V-286332MEDIUMSamsung Android 17 must be configured to not allow backup of all applications and configuration data to remote systems. - Disable Backup Services.V-286334MEDIUMSamsung Android 17 must be configured to enable authentication of personal hotspot connections to the device using a preshared key.V-286339LOWSamsung Android 17 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile).V-286340MEDIUMSamsung Android 17 must be configured to disable ad hoc wireless client-to-client connection capability.V-286342MEDIUMSamsung Android must be enrolled as a COBO device.V-286343MEDIUMSamsung Android must be configured to disallow configuration of the device's date and time.V-286344MEDIUMSamsung Android's work profile must have the DoW root and intermediate PKI certificates installed.V-286345MEDIUMSamsung Android's work profile must be configured to prevent users from adding personal email accounts to the work email app.V-286346LOWSamsung Android's work profile must be configured to enable Common Criteria (CC) mode.V-286347MEDIUMSamsung Android device users must complete required training.V-286348HIGHThe Samsung Android device must have the latest available Samsung Android operating system (OS) installed.V-286349MEDIUMThe Samsung Android device must be configured to enable Certificate Revocation List (CRL) status checking.V-286350MEDIUMThe Samsung Android device must be configured to enforce that Wi-Fi sharing is disabled.V-286351MEDIUMThe Samsung Android device work profile must be configured to enforce the system application disable list.V-286352LOWThe Samsung Android device must be configured to disable the use of third-party keyboards.V-286353MEDIUMThe Samsung Android device must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].V-286354LOWThe Samsung Android device must be configured to perform the following management function: Disable Phone Hub.V-286355MEDIUMSamsung Android 17 must disable the ability of the user to wipe the device.V-286356LOWSamsung Android 17 must disable wireless printing.V-286357LOWSamsung Android 17 must disable screen capture.V-286358MEDIUMSamsung Android 17 devices must have a Mobile Threat Detection (MTD) app installed.V-286359MEDIUMSamsung Android 17 must implement the management setting: Disable camera.V-286360MEDIUMThe Samsung Android device must be configured to disable Wi-Fi Aware for work profile apps.V-286361MEDIUMThe Samsung Android 17 device must be configured to disable Cross-Device Handoff (also called "Continuity On").V-286362MEDIUMThe Samsung Android 17 device must be configured to disable web-based artificial intelligence (AI) interactions.