GOOG-15-012500 - Google Android 15 must be configured to disable 'Private Space' use.

Information

Private Space is an Android feature that provides a separate encrypted container on the mobile device. Apps in Private Space show up in a separate container in the launcher and are hidden from the 'Recents' view, notifications, settings, and other apps when the Private Space is locked. In addition, MDM server allow list or blocklist cannot control the installation of apps into Private Space. Malware and other unauthorized apps could be installed on a DOD mobile device, which could lead to the compromise of DOD sensitive information or to an attack on the DOD network.

SFRID: FMT_MOF_EXT.1.2 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Google Android 15 device to disable 'Private Space'.

On the EMM console:

COBO:

1. Open 'Set user restrictions'.
2. Toggle 'Disallow add private profile' to 'ON'.

COPE:

1. Open 'Set user restrictions'.
2. Toggle 'Disallow add private profile' to 'ON'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_15_Y25M01_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6(1), CAT|I, CCI|CCI-000370, Rule-ID|SV-269101r1033119_rule, STIG-ID|GOOG-15-012500, Vuln-ID|V-269101

Plugin: MDM

Control ID: 9412e357404d9757af3b1fd01194fccb7b81cb416d6a3fe9b46f7811b1238594