Check: GOOG-10-010800
Google Android 10.x STIG:
GOOG-10-010800
(in versions v2 r1 through v1 r1)
Title
Google Android 10 devices must have the latest available Google Android 10 operating system installed. (Cat I impact)
Discussion
Required security features are not available in earlier operating system versions. In addition, there may be known vulnerabilities in earlier versions. SFR ID: FMT_SMF_EXT.1.1 #47
Check Content
Review device configuration settings to confirm that the Google Android device recently released version of Google Android 10 is installed. This procedure is performed on both the MDM console and the Google Android 10 device. In the MDM management console, review the version of Google Android 10 installed on a sample of managed devices. This procedure will vary depending on the MDM product. On the Google Android 10 device, to see the installed operating system version: 1. Open Settings. 2. Tap "About phone". 3. Verify "Build number". If the installed version of the Android operating system on any reviewed Google devices is not the latest released by Google, this is a finding. Google's Android operating system patch website: https://source.android.com/security/bulletin/
Fix Text
Install the latest released version of the Google Android 10 operating system on all managed Google devices. Note: Google Android device operating system updates are released directly by Google or can be distributed via the MDM.
Additional Identifiers
Rule ID: SV-237030r639236_rule
Vulnerability ID: V-237030
Group Title: PP-MDF-991000
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |