GOOG-14-013600 - The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps.

Information

Wi-Fi Aware allows direct connections between nearby devices for fast data transfer, video streaming, and multiplayer gaming. It allows full peer-to-peer device discovery and communication where two or more devices are publishing and/or subscribing to the same known service name. There is risk that sensitive DOD information could be transferred from a DOD mobile device to a non-DOD device or from Work Profile apps on a DOD device to Personal Profile apps on a non-DOD device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Google Android device to disable Wi-Fi Aware for all Work Profile apps.

On the EMM console:

For each Work Profile app, configure the NEARBY_WIFI_DEVICE permission to 'deny' to block the use of Wi-Fi Aware if the app supports this feature. If the app does not support Wi-Fi Aware, a NEARBY_WIFI_DEVICE permission may not be available.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_14_Y25M10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-278363r1134568_rule, STIG-ID|GOOG-14-013600, Vuln-ID|V-278363

Plugin: MDM

Control ID: b2c3f403a8e7e65f1de6f6c486d8ca81efdc6a339423804f14fde7fbb6184244