STIGQter STIGQter: STIG Summary: Google Android 10.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

Google Android 10 must be configured to disable multi-user modes.

DISA Rule

SV-108059r1_rule

Vulnerability Number

V-98955

Group Title

PP-MDF-301280

Rule Version

GOOG-10-004700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Google Android 10 to disable multi-user modes.

On the MDM console:

1. Open the User restrictions.
2. Open user settings.
3. Select "Disallow Add User".

Check Contents

Review documentation on the Google Android device and inspect the configuration on the Google Android device to disable multi-user modes.

This validation procedure is performed on both the MDM Administration Console and the Android 10 device.

On the MDM console, do the following:

1. Open the User restrictions.
2. Open user settings.
3. Confirm "Disallow Add User" is selected.

On the Android 10 device, do the following:

1. Go to Settings >> System >> Advanced >> Multiple users.
2. Ensure that there is no option to add a user.

If the MDM console device policy is not set to disable multi-user modes or on the Android 10 device, the device policy is not set to disable multi-user modes, this is a finding.

Vulnerability Number

V-98955

Documentable

False

Rule Version

GOOG-10-004700

Severity Override Guidance

Review documentation on the Google Android device and inspect the configuration on the Google Android device to disable multi-user modes.

This validation procedure is performed on both the MDM Administration Console and the Android 10 device.

On the MDM console, do the following:

1. Open the User restrictions.
2. Open user settings.
3. Confirm "Disallow Add User" is selected.

On the Android 10 device, do the following:

1. Go to Settings >> System >> Advanced >> Multiple users.
2. Ensure that there is no option to add a user.

If the MDM console device policy is not set to disable multi-user modes or on the Android 10 device, the device policy is not set to disable multi-user modes, this is a finding.

Check Content Reference

M

Target Key

3581

Comments