Android 13 BYOAD STIG Checklist
18 items · Security · Hard difficulty · 1 day
Practical steps to implement Android 13 BYOAD STIG controls.
-
Download the official Android 13 BYOAD STIG document
Get the latest STIG from DoD Cyber Exchange or public.cyber.mil if needed.
-
Review and highlight applicable STIG controls
Identify controls relevant to your BYOAD policy and device types.
-
Inventory all BYOAD devices and owners
Record model, OS build, owner, and enrollment status.
-
Classify devices by risk and allowed access
Group by sensitivity of data and permitted enterprise resources.
-
Define and enforce mandatory MDM enrollment
Require MDM for access to enterprise apps and data.
-
Configure enrollment profiles and device policies in MDM
Include restrictions, update channels, and compliance checks.
-
Enforce OS updates and patch management via MDM
Set required update windows and automatic installation where possible.
-
Enable and verify device encryption
Ensure full-disk/file-based encryption is active for all devices.
-
Enforce strong screen lock and authentication policies
Set PIN/biometric rules, timeout, and lock requirements.
-
Disable developer options and USB debugging
Prevent easy device compromise and unauthorized access.
-
Restrict app installation to approved sources
Allow Play Store and enterprise app store; block unknown sources.
-
Enable Play Protect and mobile malware scanning
Turn on built-in threat protection and regular scans.
-
Verify SELinux is enforcing and enable integrity checks
Confirm system integrity and enforcement mode on devices.
-
Configure VPN and network access controls for enterprise resources
Use per-app VPN or device VPN for approved traffic.
-
Enable remote wipe, lock, and lost-device capabilities
Ensure administrators can quickly protect data on lost/stolen devices.
-
Enable logging and forward audit logs to a central SIEM
Collect authentication, policy, and device events for monitoring.
-
Test STIG settings in a representative lab environment
Validate functionality and user impact before production rollout.
-
Document accepted deviations and obtain AO approval
Record risks, compensating controls, and approval from the Authorizing Official.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.