Google Android 13 BYOAD STIG Version Comparison
Google Android 13 BYOAD Security Technical Implementation Guide
Comparison
There are 1 differences between versions v1 r1 (Oct. 4, 2023) (the "left" version) and v1 r2 (April 24, 2024) (the "right" version).
Check GOOG-13-701100 was changed between these two versions. Green, underlined text was added, red, struck-out text was removed.
The regular view of the left check and right check may be easier to read.
Text Differences
Title
Google Android 13 must prohibit DOD VPN profiles in the Personal Profile.
Check Content
Review the list of VPN profiles in the Personal Profile and determine if any VPN profiles are listed. If so, verify the VPN profiles are not configured with a DOD network VPN profile. This validation procedure is performed on the iOS device only. On the iPhone and iPad: 1. Open the Settings app. 2. Tap "Network & internet". 3. Tap "VPN" and determine if any VPN profiles exist. 4. If not, the requirement has been met. 5. If there are VPN profiles, open each VPN profile. 6. profile. If Verify no DOD network VPN profiles are listed. If any VPN profiles are installed in the Personal Profile and they have a DOD network VPN profile configured, this is a finding. Note: This setting cannot be managed by the MDM administrator and is a User-Based Enforcement (UBE) requirement.
Discussion
If DOD VPN profiles are configured in the Personal Profile DOD sensitive data world be at risk of compromise and the DOD network could be at risk of being attacked by malware installed on the device. SFR ID: FMT_SMF_EXT.1.1 #3
Fix
Do not configure DOD VPN profiles in the Personal Profile.