GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use.

Information

Private Space is an Android feature that provides a separate encrypted container on the mobile device. Apps in Private Space show up in a separate container in the launcher and are hidden from the 'Recents' view, notifications, settings, and other apps when the private space is locked. In addition, an MDM server allowlist or blocklist cannot control the installation of apps into Private Space. Malware and other unauthorized apps could be installed on a DOD mobile device, which could lead to the compromise of DOD sensitive information or to an attack on the DOD network.

SFR ID: FMT_MOF_EXT.1.2 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Google Android 16 device to disable 'Private Space'.

On the EMM console:

COBO:

1. Open 'Set user restrictions'.
2. Toggle 'Disallow add private profile' to 'ON'.

COPE:

1. Open 'Set user restrictions'.
2. Toggle 'Disallow add private profile' to 'ON'.

Configuration API: DISALLOW_ADD_PRIVATE_PROFILE

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_16_Y25M08_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6(1), CAT|I, CCI|CCI-000370, Rule-ID|SV-276783r1140141_rule, STIG-ID|GOOG-16-012500, Vuln-ID|V-276783

Plugin: MDM

Control ID: 995e0349d636e328149af2dfa03dff696fc1e00e329b522ca1def10fb903abd8