1.13 Ensure 'Smart Lock' is set to Disabled

Information

Disable Smart Lock.

Rationale:

Smart Lock detects device presence and its circumstances and automatically keeps it unlocked even if the device has a screen password, pin or pattern enabled. Using Smart Lock does not require you to manually unlock the device every time if the pre-defined circumstances are met. As a best practice, do not set the device to get unlocked automatically. For example, if your device gets stolen and if it is taken to a location pre-defined in Smart Lock, it would automatically unlock. Similarly, if someone could replay your voice, the device would automatically unlock.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Smart Lock:

* Tap the System Settings Gear Icon.
* Scroll to Personal.
* Tap Security.
* Scroll to Advanced.
* Tap Trust agents.
* Toggle Smart Lock (Google) to Off position.

Impact:

The device would need to be manually unlocked everytime.

See Also

https://workbench.cisecurity.org/files/1477

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: MDM

Control ID: 19a7a7c7dd20edf34118de455c39280ec35b21a1e720f49938200b1e9ee8fe0e