1.13 Ensure 'Find My Device' is set to 'Enabled'

Information

Find My Device allows users to remotely locate, lock, or erase their device in case it is lost or stolen.

The recommended state for this setting is: Enabled.

Rationale:

By enabling Find My Device, a user can remotely locate the device, ring the device, lock, or erase the device data. This helps to protect any sensitive data or personal information that may be stored on the device. It also increases the chances of recovering the device or having it returned to the owner, as it can provide location information to law enforcement or other authorities.

Impact:

Google may track device location anytime.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to enable Find My Device:

Open phone's Settings app.

Tap Security.

Tap Find My Device.

Toggle slider to the ON position.

Default Value:

By default, Find My Device is not enabled.

See Also

https://workbench.cisecurity.org/benchmarks/23192

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-19

Plugin: MDM

Control ID: 965a380e49df75b9680506286991e02cc1c88e281fd3027f9cefa399de7376b8