SV-108057r1_rule
V-98953
PP-MDF-301260
GOOG-10-004500
CAT II
10
Configure the Google Android 10 to enable the access control policy that prevents [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].
NOTE: All application data is inherently sandboxed and isolated from other applications. In order to disable copy/paste on the MDM Console:
1. Open User restrictions.
2. Select "Disallow cross profile copy/paste".
3. Select "Disallow sharing data into the profile".
Review documentation on the Google Android device and inspect the configuration on the Google Android device to verify the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.
This validation procedure is performed only on the MDM Administration Console.
On the MDM console, do the following:
1. Open User restrictions.
2. Select "Disallow cross profile copy/paste".
3. Select "Disallow sharing data into the profile".
If the MDM console device policy is not set to disable data sharing between profiles, this is a finding.
V-98953
False
GOOG-10-004500
Review documentation on the Google Android device and inspect the configuration on the Google Android device to verify the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.
This validation procedure is performed only on the MDM Administration Console.
On the MDM console, do the following:
1. Open User restrictions.
2. Select "Disallow cross profile copy/paste".
3. Select "Disallow sharing data into the profile".
If the MDM console device policy is not set to disable data sharing between profiles, this is a finding.
M
3581