KNOX-07-913300 - The Samsung must implement the management setting: Disable sharing of calendar information outside the Container.

Information

Calendar events can include potentially DoD-sensitive data such as names, contacts, dates and times, and locations. If made available outside the container, this information will be accessible to personal applications, resulting in potential compromise of DoD data.

SFR ID: FMT_SMF_EXT.1.1 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Samsung Android 7 with Knox to enforce disabled sharing of calendar information outside the Container.

On the MDM console, disable the "Allow calendar info outside container" setting in the "Android Knox Container >> Container Restrictions" rule.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Samsung_Android_OS_7_with_Knox_2-x_V1R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-91337r1_rule, STIG-ID|KNOX-07-913300, Vuln-ID|V-76641

Plugin: MDM

Control ID: 9892b6bc7b842e2145d9f25706c91d0ff47850e28e3e5b36294d492bcf402079