Google Android 15 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-267462GOOG-15-012200SV-267462r1033049_ruleCCI-002235medium
Description
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFRID: FMT_MOF_EXT.1.2 #24
STIGDate
Google Android 15 COBO Security Technical Implementation Guide2024-12-05

Details

Check Text (C-267462r1033049_chk)

Review the device configuration to confirm that the USB port is disabled except for charging the device. On the EMM console: 1. Open "Set user restrictions". 2. Verify “Disallow USB file transfer” is set to "ON". If on EMM console the USB port is not disabled (“Disallow USB file transfer” is set to "ON"), this is a finding.

Fix Text (F-71289r1033048_fix)

Configure Google Android 15 device to disable the USB port (except for charging the device). COPE and COBO: On the EMM console: 1. Open "Set user restrictions". 2. Toggle “Disallow USB file transfer” to "ON".