The user agreement must include a description of what personal data and information is being monitored, collected, or managed by the EMM system or deployed agents or tools.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-272517KNOX-15-802100SV-272517r1098324_ruleCCI-000366low
Description
DOD policy states BYOAD owners must sign a user agreement and be made aware of what personal data and activities will be monitored by the Enterprise by including this information in the user agreement. Reference: DOD policy "Use of Non-Government Mobile Devices" (3.a.(3)ii, and 3.c.(4)). SFR ID: FMT_SMF_EXT.1.1 #47
STIGDate
Samsung Android 15 BYOAD Security Technical Implementation Guide2025-04-29

Details

Check Text (C-272517r1098324_chk)

Verify the user agreement includes a description of what personal data and information is being monitored, collected, or managed by the EMM system or deployed agents or tools. If the user agreement does not include a description of what personal data and information is being monitored, collected, or managed by the EMM system or deployed agents or tools, this is a finding.

Fix Text (F-76503r1098323_fix)

Include a description of what personal data and information is being monitored, collected, or managed by the EMM system or deployed agents or tools in the user agreement.