Check: KNOX-09-000820
Samsung OS 9 with Knox 3.x COBO Use Case KPE(AE) Deployment STIG:
KNOX-09-000820
(in versions v1 r4 through v1 r1)
Title
Samsung Android must be configured to enforce that Wi-Fi Sharing is disabled. (Cat II impact)
Discussion
Wi-Fi Sharing is an optional configuration of Wi-Fi Tethering/Mobile Hotspot, which allows the device to share its Wi-Fi connection with other wirelessly connected devices instead of its mobile (cellular) connection. Wi-Fi Sharing grants the "other" device access to a corporate Wi-Fi network and may possibly bypass the network access control mechanisms. This risk can be partially mitigated by requiring the use of a preshared key for personal hotspots. SFR ID: FMT_SMF_EXT.1.1 #47
Check Content
Review device configuration settings to confirm Wi-Fi Sharing is disabled. Mobile Hotspot must be enabled in order to enable Wi-Fi Sharing. If the Authorizing Official (AO) has not approved Mobile Hotspot, and it has been verified as disabled on the MDM console, the following guidance is not applicable. This setting cannot be managed by the MDM administrator and is a User-Based Enforcement (UBE) requirement. On the Samsung Android device, do the following: 1. Open Settings. 2. Tap "Connections". 3. Tap "Mobile Hotspot and Tethering". 4. Tap "Mobile hotspot". 5. Verify that "Wi-Fi sharing" is disabled. If on the Samsung Android device "Wi-Fi sharing" is enabled, this is a finding.
Fix Text
Configure Samsung Android to disable Wi-Fi Sharing. Mobile Hotspot must be enabled in order to enable Wi-Fi Sharing. If the AO has not approved Mobile Hotspot, and it has been disabled on the MDM console, the following guidance is not applicable. On the Samsung Android device, do the following: 1. Open Settings. 2. Tap "Connections". 3. Tap "Mobile Hotspot and Tethering". 4. Tap "Mobile hotspot". 5. Disable "Wi-Fi sharing" if it is enabled.
Additional Identifiers
Rule ID: SV-217684r388482_rule
Vulnerability ID: V-217684
Group Title: PP-MDF-991000
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |