GOOG-15-009400 - Google Android 15 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile) - SPP.

Information

Some Bluetooth profiles provide the capability for remote transfer of sensitive DOD data without encryption or otherwise do not meet DOD IT security policies and therefore must be disabled.

SFRID: FMT_SMF_EXT.1.1/BLUETOOTH BT-8

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the Google Android 15 device to disable Bluetooth, or if the AO has approved the use of Bluetooth (for example, for car hands-free use), train the user to connect to only authorized Bluetooth devices using only HSP, HFP, or SPP Bluetooth capable devices (UBE).

To disable Bluetooth, use the following procedure:

On the EMM console:

COBO:

1. Open 'User restrictions' section.
2. Toggle 'Disallow Bluetooth' to 'ON'.

COPE:

1. Open 'User restrictions on parent' section.
2. Toggle 'Disallow Bluetooth' to 'ON'.

The user training requirement is satisfied in requirement GOOG-15-009800.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_15_Y25M01_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(1)(b), 800-53|CM-7a., CAT|III, CCI|CCI-000381, CCI|CCI-001761, Rule-ID|SV-267545r1031820_rule, STIG-ID|GOOG-15-009400, Vuln-ID|V-267545

Plugin: MDM

Control ID: 5a9092b78dcfb1cd1969013fed251fc7ba466cb6bbd31d581a18e54afc2cd194