GOOG-15-013600 - The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps.

Information

Wi-Fi Aware allows direct connections between nearby devices for fast data transfer, video streaming, and multiplayer gaming. It allows full peer-to-peer device discovery and communication where two or more devices are publishing and/or subscribing to the same known service name. There is risk that sensitive DOD information could be transferred from a DOD mobile device to a non-DOD device or from Work Profile apps on a DOD device to Personal Profile apps on a non-DOD device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Google Android device to disable Wi-Fi Aware for all Work Profile apps.

On the EMM console:

For each Work Profile app, configure the NEARBY_WIFI_DEVICE permission to 'deny' to block the use of Wi-Fi Aware if the app supports this feature. If the app does not support Wi-Fi Aware, a NEARBY_WIFI_DEVICE permission may not be available.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_15_Y25M10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-278365r1134574_rule, STIG-ID|GOOG-15-013600, Vuln-ID|V-278365

Plugin: MDM

Control ID: 29c26a51b2049e4247b1d2bb24994cecebd486c1860e63ec6d0cf04e1c44e12d