2.3 Ensure 'Back up to Google Drive' is Disabled

Information

Disable Backup to Google Drive.

Rationale:

You can back up content, data, and settings from your device to your Google Account. You can then later restore your backed-up information to another device. Due to privacy concerns, backing up personal data such as text messages, emails, photos and contacts to any third party is not recommended unless you accept the risk of sharing the data with the 3rd party. Moreover, if you are using a personal device for business apps such as emails, that data might be backed up as well in the Google Drive related to your personal account and might be exposed. Hence, disable the automatic backup to Google drive and carefully choose what data backup you need.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Back up to Google Drive:

* Tap System Settings Gear Icon.
* Scroll to Personal.
* Tap Backup & reset.
* Tap Device Backup.
* Tap Back up to Google Drive.
* Toggle it to Off position.
* Tap OK on warning popup.

Impact:

A backup of the device will not be taken and hence restoration would not be possible. Also, the user would have to carefully choose the data to be backed up and manually back it up periodically.

See Also

https://workbench.cisecurity.org/files/1477

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: MDM

Control ID: f82a0a1efca6954fd1a061372bb24ccb99816a82564ea185f9bb9d81b9a141b8