GOOG-15-006750 - Google Android 15 allow list must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini.

Information

Sensitive DOD data could be exposed when an AI app processes device data in the cloud.

SFRID: FMT_SMF.1.1 #8

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Google Android 15 device application allow list to exclude AI applications that process device data in the cloud, including Google Gemini.

Review managed Google Android 15 device configuration settings to determine if the mobile device has an AI application that processes device data in the cloud, including Google Gemini.

On the EMM console:

1. Review the list of selected Managed Google Play apps.
2. Verify no AI applications that processes device data in the cloud, including Google Gemini, are included.

Note: This restriction does not include Gemini Nano. Gemini Nano is a built-in capability of Android 15 and processes device data on the device.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_15_Y25M01_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-7, CAT|II, CCI|CCI-000803, Rule-ID|SV-267533r1033066_rule, STIG-ID|GOOG-15-006750, Vuln-ID|V-267533

Plugin: MDM

Control ID: 181d6cda1bf6ef8f66cbc5637fe6bcc8625abec78fa9048c2a9b5d96ad9de6bc