1.11 Do not root your device

Information

Do not root your device.
The recommended state for this setting is: Do not Root.

Rationale:

Rooting your Android device breaks the user level restrictions put by the Android operating system. This significantly opens up the device to allow literally any privileged action. Rooting enables any form of alteration to the device. This puts the device at a much greater risk because any vulnerability can be exploited without any restrictions. This also voids the warranty and future security updates are problematic to install. Hence, for all user purposes, do not root your device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow your device manufacturer support/documentation/community to completely un-root your device.
Impact:

None

Default Value:

By default, devices are not rooted and run with user level restrictions.

See Also

https://workbench.cisecurity.org/files/2466

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4), CSCv6|5

Plugin: MDM

Control ID: 4612fe2499ce9e59155146be3c0350fb0792535737651e451027a208134af8fd