GOOG-16-006750 - Google Android 16 allowlist must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini - AI applications that process device data in the cloud, including Google Gemini.

Information

Sensitive DOD data could be exposed when an AI app processes device data in the cloud.

SFR ID: FMT_SMF.1.1 #8

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Google Android 16 device application allowlist to exclude AI applications that process device data in the cloud, including Google Gemini.

Note: This restriction does not include Gemini Nano. Gemini Nano is a built-in capability of Android 16 and processes device data on the device. Refer to the STIG Supplemental document, Section 2, Artificial Intelligence Restrictions, for more information.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_16_Y25M08_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-7, CAT|II, CCI|CCI-000803, Rule-ID|SV-276858r1140366_rule, STIG-ID|GOOG-16-006750, Vuln-ID|V-276858

Plugin: MDM

Control ID: e82c9004208a066648e7d9ab29d95e5e6fdcb02204f18ba1618137c78023c298