Samsung Android must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-255140KNOX-13-210040SV-255140r958402_ruleCCI-000057medium
Description
The screen-lock timeout helps protect the device from unauthorized access. Devices without a screen-lock timeout provide an opportunity for adversaries who gain physical access to the mobile device through loss, theft, etc. Such devices are much more likely to be in an unlocked state when acquired by an adversary, thus granting immediate access to the data on the mobile device and possibly access to DOD networks. SFR ID: FMT_SMF_EXT.1.1 #2a
STIGDate
Samsung Android OS 13 with Knox 3.x COPE Security Technical Implementation Guide2024-12-06

Related Frameworks

3 paths across 3 frameworks
NIST 800-531 mapping
AC-11
1.00
  • DISA · 2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
3.1.10
1.00
  • DISA · 2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000057
1.00
  • DISA · 2 · disa_xccdf · related

Details

Check Text (C-255140r958402_chk)

Verify requirement KNOX-13-210030 (minimum password quality) has been implemented. If a "minimum password quality" has not been implemented, this is a finding.

Fix Text (F-58697r867356_fix)

Implement a "minimum password quality" (see requirement KNOX-13-210030).