STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 1 hour ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to STIGs

Samsung Android OS 17 with Knox 3.x COPE Security Technical Implementation Guide

Version

V1R1

Release Date

Aug 7, 2026

SCAP Benchmark ID

SS_Android_OS_17_KPE_3-x_COPE_STIG

Total Checks

48

Tags

mobile
CAT I: 2CAT II: 38CAT III: 8

This Security Technical Implementation Guide is published as a tool to improve the security of Department of War (DoW) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (48)

V-286399MEDIUMSamsung Android 17 must allow only the administrator (EMM) to install/remove DoW root and intermediate PKI certificates.V-286403LOWSamsung Android 17 must [DoW-restricted selection: Allow the user to choose whether to accept the certificate in these cases, not accept the certificate] when it cannot establish a connection to determine the validity of a certificate.V-286413MEDIUMSamsung Android 17 must be configured to enforce a minimum password length of six characters.V-286414MEDIUMSamsung Android 17 must be configured to not allow passwords that include more than four repeating or sequential characters.V-286415MEDIUMSamsung Android 17 must be configured to lock the display after 15 minutes (or less) of inactivity.V-286416MEDIUMSamsung Android 17 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity - Disable trust agents.V-286417MEDIUMSamsung Android 17 must be configured to not allow more than 10 consecutive failed authentication attempts.V-286418MEDIUMSamsung Android 17 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DoW-approved commercial app repository, MDM server, mobile application store].V-286419MEDIUMSamsung Android 17 must be configured to enforce an application installation policy by specifying an application allow list that restricts applications by the following characteristic: Names.V-286420MEDIUMThe Samsung Android 17 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DoW cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DoW servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with the user; - Payment processing; - Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers; - Backs up its own data to a remote system; and - Renders TV shows and movies.V-286421MEDIUMThe Samsung Android 17 allow list must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini.V-286422MEDIUMSamsung Android 17 must be configured to not display the following (work profile) notifications when the device is locked: All notifications.V-286424HIGHSamsung Android 17 must be configured to enable encryption for data at rest on removable storage media or, alternately, the use of removable storage media must be disabled.V-286425MEDIUMSamsung Android 17 must be configured to disable authentication mechanisms providing user access to protected data other than a Password Authentication Factor: Face authentication factor (unless NIAP-validated).V-286428MEDIUMSamsung Android 17 must be configured to disable developer modes.V-286430MEDIUMThe Samsung Android 17 work profile must be configured to enable audit logging.V-286432LOWSamsung Android 17 must be configured to display the DoW advisory warning message at startup or each time the user unlocks the device.V-286434MEDIUMSamsung Android 17 must be configured to disable USB mass storage mode.V-286435MEDIUMSamsung Android 17 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.V-286436MEDIUMSamsung Android 17 must be configured to not allow backup of [all applications, configuration data] to remote systems. (This requirement applies to the work profile for COPE.) - Disable Data Sync Framework.V-286438MEDIUMSamsung Android 17 must be configured to enable authentication of personal hotspot connections to the device using a preshared key.V-286440MEDIUMSamsung Android 17 must be configured to disable exceptions to the access control policy that prevent application processes and groups of application processes from accessing all data stored by other application processes and groups of application processes.V-286444LOWSamsung Android 17 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile).V-286445MEDIUMSamsung Android 17 must be configured to disable ad hoc wireless client-to-client connection capability.V-286447MEDIUMSamsung Android must be enrolled as a COPE device.V-286448MEDIUMSamsung Android must be configured to disallow configuration of the device's date and time.V-286449MEDIUMSamsung Android's work profile must have the DoW root and intermediate PKI certificates installed.V-286450MEDIUMSamsung Android's work profile must be configured to prevent users from adding personal email accounts to the work email app.V-286451LOWSamsung Android's work profile must be configured to enable Common Criteria (CC) mode.V-286452MEDIUMSamsung Android device users must complete required training.V-286453HIGHThe Samsung Android device must have the latest available Samsung Android operating system (OS) installed.V-286454MEDIUMThe Samsung Android device must be configured to enable Certificate Revocation List (CRL) status checking.V-286455MEDIUMThe Samsung Android device must be configured to enforce that Wi-Fi sharing is disabled.V-286456MEDIUMThe Samsung Android device work profile must be configured to enforce the system application disable list.V-286457MEDIUMThe Samsung Android device must be provisioned as a fully managed device and configured to create a work profile.V-286458MEDIUMThe Samsung Android device work profile must be configured to disable automatic completion of work space internet browser text input.V-286459MEDIUMThe Samsung Android device work profile must be configured to disable the autofill services.V-286460LOWThe Samsung Android device must be configured to disable the use of third-party keyboards.V-286461MEDIUMThe Samsung Android device must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].V-286462LOWThe Samsung Android device must be configured to perform the following management function: Disable Phone Hub.V-286463MEDIUMSamsung Android 17 must disable the ability of the user to wipe the device.V-286464LOWSamsung Android 17 must disable wireless printing.V-286465LOWSamsung Android 17 must disable screen capture.V-286466MEDIUMSamsung Android 17 devices must have a Mobile Threat Detection (MTD) app installed.V-286467MEDIUMSamsung Android 17 must implement the management setting: Disable camera.V-286468MEDIUMThe Samsung Android device must be configured to disable Wi-Fi Aware for work profile apps.V-286469MEDIUMThe Samsung Android 17 device must be configured to disable Cross-Device Handoff (also called "Continuity On").V-286470MEDIUMThe Samsung Android 17 device must be configured to disable web-based artificial intelligence (AI) interactions.