UCF STIG Viewer Logo

Android 13 devices must be configured to disable the use of third-party keyboards (work profile only).


Overview

Finding ID Version Rule ID IA Controls Severity
V-258496 GOOG-13-710900 SV-258496r929304_rule Low
Description
Many third-party keyboard applications are known to contain malware. SFR ID: FMT_SMF_EXT.1.1 #47
STIG Date
Google Android 13 BYOAD Security Technical Implementation Guide 2023-09-19

Details

Check Text ( C-62236r929302_chk )
Review the managed Google Android 13 configuration settings to confirm that no third-party keyboards are enabled (work profile only).

This procedure is performed on the EMM console.

On the EMM console:

1. Open "Input methods".
2. Tap "Set input methods".
3. Verify only the approved keyboards are selected.

If unapproved third-party keyboards are allowed in the work profile, this is a finding.
Fix Text (F-62145r929303_fix)
Configure the Google Android 13 device to disallow the use of third-party keyboards (work profile only).

On the EMM console:

1. Open "Input methods".
2. Tap "Set input methods".
3. Select only the approved keyboards.

Additionally, admins can configure application allowlists for Google Play so no third-party keyboards are available for user installation.