1.28 Review existing user profiles periodically

Information

Review any user profiles on the device. Remove those that are no longer required.

Rationale:

Users and the guest profile can do most of the same things as the device's owner, but each profile has its own storage space. As a result, additional users could install malicious apps or carry out other activities that compromise overall device security. Therefore, reviewing and removing unnecessary user profiles should be done periodically.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to delete any unnecessary profiles:

Open phone's Settings app.

Tap System.

Tap Advanced.

Tap Multiple users.

Tap any unnecessary profile.

Tap Delete User.

See Also

https://workbench.cisecurity.org/benchmarks/23192

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: MDM

Control ID: 6eebe761aca9df56101ace5af9f6ef4cafe387108e5d94f92b55670672505d20