| 1.18 Ensure 'Improve harmful app detection' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
| GOOG-09-000500 - The Google Android Pie must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Google Android 9.x v2r1 | MDM | ACCESS CONTROL |
| GOOG-09-006100 - The Google Android Pie must be configured to generate audit records for the following auditable events: detected integrity violations. | MobileIron - DISA Google Android 9.x v2r1 | MDM | AUDIT AND ACCOUNTABILITY |
| GOOG-09-009600 - Google Android Pie must be provisioned as a fully managed device and configured to create a work profile. | MobileIron - DISA Google Android 9.x v2r1 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-09-009800 - Google Android Pie work profile must be configured to disable automatic completion of work space Internet browser text input. | MobileIron - DISA Google Android 9.x v2r1 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-09-999999 - All Google Android 9 installations must be removed. | AirWatch - DISA Google Android 9.x v2r1 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-10-000500 - Google Android 10 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Google Android 10.x v2r1 | MDM | ACCESS CONTROL |
| GOOG-10-009600 - Google Android 10 must be provisioned as a fully managed device and configured to create a work profile. | MobileIron - DISA Google Android 10.x v2r1 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-11-000800 - Google Android 11 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DoD-approved commercial app repository, EMM server, mobile application store]. | MobileIron - DISA Google Android 11 COPE v2r1 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-11-002300 - Google Android 11 must be configured to disable trust agents. | MobileIron - DISA Google Android 11 COPE v2r1 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-11-009600 - Google Android 11 must be provisioned as a fully managed device and configured to create a work profile. | MobileIron - DISA Google Android 11 COPE v2r1 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-12-006300 - Google Android 12 must be configured to lock the display after 15 minutes (or less) of inactivity. | AirWatch - DISA Google Android 12 COPE v1r2 | MDM | ACCESS CONTROL |
| GOOG-12-006800 - Google Android 12 must be configured to not display the following (work profile) notifications when the device is locked: | AirWatch - DISA Google Android 12 COPE v1r2 | MDM | ACCESS CONTROL |
| GOOG-12-007700 - Google Android 12 must be configured to display the DoD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 12 COPE v1r2 | MDM | ACCESS CONTROL |
| GOOG-12-010300 - Google Android 12 must be provisioned as a fully managed device and configured to create a work profile. | MobileIron - DISA Google Android 12 COPE v1r2 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-13-010000 - Google Android 13 must have the DOD root and intermediate PKI certificates installed. | AirWatch - DISA Google Android 13 COPE STIG v2r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-13-010100 - The Google Android 13 work profile must be configured to prevent users from adding personal email accounts to the work email app. | AirWatch - DISA Google Android 13 COPE STIG v2r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-13-710000 - Google Android 13 must have the DOD root and intermediate PKI certificates installed (work profile only). | AirWatch - DISA Google Android 13 BYOAD v1r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-13-710100 - The Google Android 13 work profile must be configured to prevent users from adding personal email accounts to the work email app. | AirWatch - DISA Google Android 13 BYOAD v1r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-13-710400 - The Google Android 13 work profile must be configured to disable automatic completion of workspace internet browser text input. | AirWatch - DISA Google Android 13 BYOAD v1r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-006800 - Google Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection: | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-007200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-007700 - Google Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-007700 - Google Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-008400 - Google Android 14 must be configured to disable USB mass storage mode. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-009500 - Google Android 14 must be configured to disable ad hoc wireless client-to-client connection capability. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-706500 - Google Android 14 must be configured to enforce an application installation policy by specifying one or more authorized application repositories. | MobileIron - DISA Google Android 14 BYOAD v1r2 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-710300 - Google Android 14 must be provisioned as a BYOAD device (Android work profile for employee-owned devices [BYOD]) - Android work profile for employee-owned devices [BYOD]. | MobileIron - DISA Google Android 14 BYOAD v1r2 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-15-006800 - Google Android 15 must be configured to not display the following (work profile) notifications when the device is locked: [selection: | AirWatch - DISA Google Android 15 COBO STIG v1r5 | MDM | ACCESS CONTROL |
| GOOG-15-007200 - Google Android 15 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation. | AirWatch - DISA Google Android 15 COBO STIG v1r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-15-007400 - Google Android 15 must be configured to disable developer modes. | AirWatch - DISA Google Android 15 COBO STIG v1r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-15-007700 - Google Android 15 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 15 COPE STIG v1r5 | MDM | ACCESS CONTROL |
| GOOG-15-008400 - Google Android 15 must be configured to disable USB mass storage mode. | AirWatch - DISA Google Android 15 COBO STIG v1r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-16-006300 - Google Android 16 must be configured to lock the display after 15 minutes (or less) of inactivity - or less of inactivity. | AirWatch - DISA Google Android 16 COPE STIG v1r1 | MDM | ACCESS CONTROL |
| GOOG-16-006300 - Google Android 16 must be configured to lock the display after 15 minutes (or less) of inactivity - or less of inactivity. | AirWatch - DISA Google Android 16 COBO STIG v1r3 | MDM | ACCESS CONTROL |
| GOOG-16-007200 - Google Android 16 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation. | AirWatch - DISA Google Android 16 COBO STIG v1r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-16-007200 - Google Android 16 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation. | AirWatch - DISA Google Android 16 COPE STIG v1r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-16-007400 - Google Android 16 must be configured to disable developer modes. | AirWatch - DISA Google Android 16 COBO STIG v1r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-16-007400 - Google Android 16 must be configured to disable developer modes. | AirWatch - DISA Google Android 16 COPE STIG v1r1 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-16-007700 - Google Android 16 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 16 COBO STIG v1r3 | MDM | ACCESS CONTROL |
| GOOG-16-007700 - Google Android 16 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 16 COPE STIG v1r1 | MDM | ACCESS CONTROL |
| GOOG-16-007700 - Google Android 16 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 16 COPE STIG v1r3 | MDM | ACCESS CONTROL |
| GOOG-16-008400 - Google Android 16 must be configured to disable USB mass storage mode. | AirWatch - DISA Google Android 16 COPE STIG v1r3 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-16-008400 - Google Android 16 must be configured to disable USB mass storage mode. | AirWatch - DISA Google Android 16 COBO STIG v1r3 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-16-012300 - Google Android 16 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates - EMM to install/remove DOD root and intermediate PKI certificates. | MobileIron - DISA Google Android 16 COPE STIG v1r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-16-012400 - Google Android 16 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub - MDM to perform the following management function: Disable Phone Hub. | AirWatch - DISA Google Android 16 COBO STIG v1r3 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| HONW-13-009400 - Honeywell Android 13 must be configured to disable Bluetooth or configured via User-Based Enforcement (UBE) to allow Bluetooth for only Headset Profile (HSP), Hands-Free Profile (HFP), and Serial Port Profile (SPP). | AirWatch - DISA Honeywell Android 13 COPE STIG v1r1 | MDM | CONFIGURATION MANAGEMENT |
| ZEBR-14-010900 - Android 14 devices must be configured to disable the use of third-party keyboards. | AirWatch - DISA Zebra Android 14 COPE STIG v1r2 | MDM | CONFIGURATION MANAGEMENT |
| ZEBR-14-010900 - Android 14 devices must be configured to disable the use of third-party keyboards. | AirWatch - DISA Zebra Android 14 COBO STIG v1r2 | MDM | CONFIGURATION MANAGEMENT |
| ZEBR-14-012400 - Zebra Android 14 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub - MDM to perform the following management function: Disable Phone Hub. | MobileIron - DISA Zebra Android 14 COBO STIG v1r2 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |