1.12 Ensure 'Smart Lock' is set to 'Disabled'

Information

Smart Lock detects the device's presence and automatically keeps it unlocked even if it has a screen password, pin or pattern enabled. Using Smart Lock allows the device to be unlocked if preconditions are met.

The recommended state for this setting is: Disabled.

Rationale:

Smart Lock detects the device's presence and automatically keeps it unlocked even if it has a screen password, pin or pattern enabled. Using Smart Lock allows the device to be unlocked if preconditions are met. As a best practice, do not set the device to unlock automatically. For example, if the device is stolen and taken to a location pre-defined in Smart Lock, it would automatically unlock. Similarly, if someone could replay the voice, the device would automatically unlock.

Impact:

The device would need to be manually unlocked every time.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Smart Lock:

Open phone's Settings app.

Tap Security.

Tap Advanced.

Tap Trust agents.

Toggle Smart Lock (Google) to OFF position.

Default Value:

By default, Smart Lock is enabled.

See Also

https://workbench.cisecurity.org/benchmarks/23192