GOOG-16-011000 - Android 16 devices must be configured to enable Common Criteria (CC) Mode - CC Mode.

Information

The CC Mode feature is a superset of other features and behavioral changes that are mandatory MDFPP requirements. If CC Mode is not implemented, the device will not be operating in the NIAP-certified compliant CC Mode of operation.

CC Mode implements the following behavioral/functional changes: How the Bluetooth and Wi-Fi keys are stored using different types of encryption.

SFR ID: FMT_SMF.1.1 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Google Android 16 device to implement CC Mode.

On the EMM console:

COBO and COPE:

1. Open Device owner management.
2. Toggle 'Enable Common Criteria mode' to 'ON'.

Configuration API: setCommonCriteriaModeEnabled

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_16_Y25M08_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-276884r1140444_rule, STIG-ID|GOOG-16-011000, Vuln-ID|V-276884

Plugin: MDM

Control ID: 13eb7947adc00ba7a98d57875873521c907a1a5e37eb030862309c8b5ef2490f