Android 14 BYOAD STIG Compliance Checklist
21 items · Security · Medium difficulty · 1 day
Implement Android 14 BYOAD security controls and verify STIG compliance.
-
Download the standalone XCCDF STIG
Get XCCDF 1.1.4 from https://cyber.mil/ or https://public.cyber.mil/
-
Verify STIG ID, version and publication dates
Confirm Checklist ID 1230, version Y25M10, pub 03/13/2024, last modified 12/12/2025.
-
Confirm target CPE and OS version is Android 14
STIG targets cpe:/o:google:android:14.0
-
Confirm device compatibility for BYOAD deployment
Ensure Samsung devices are capable of running Android 14 per STIG scope.
-
Ensure NIAP-certified data separation technology is used
Use NIAP-certified solution compliant with MDFPP v3.3 (BYOD use case).
-
Add screenshot prohibition to user agreements
Include: “Screenshots will not be taken of any ‘work’ related managed data.”
-
Review Section 2.4 operational considerations in the supplemental
Read operational guidance the site and AO should review before deployment.
-
Assign Approving Official (AO) and site authority
Designate AO to approve BYOAD use and document authority.
-
Configure the managed operational environment per STIG
Set up Managed / SSLF environment and controls described in the STIG.
-
Apply work profile separation settings
Configure work vs personal app/data separation in the managed profile.
-
Configure app controls and data flow rules
Enforce allowed apps, restrict data sharing, and control exports.
-
Enable hardware-backed keystore and enforced encryption
Use hardware keystore and require full-disk or file-based encryption.
-
Implement security policies for managed work apps
Apply device policies, app restrictions, and network access controls.
-
Verify OS and security patch levels are up to date
Confirm devices run supported Android 14 security patch levels.
-
Ensure compliance with DODI 8500.01
Map STIG controls to DODI 8500.01 requirements and document compliance.
-
Conduct functional and security testing of BYOAD setup
Perform tests for separation, data leakage, and policy enforcement.
-
Train users on BYOAD rules and screenshot prohibition
Brief users on acceptable use, privacy, and handling of work data.
-
Document approvals, configurations, and change history
Record AO approvals, implemented controls, and STIG revision history.
-
Establish incident reporting process and point of contact
Publish reporting steps and POC email for security incidents.
-
Submit comments or revision requests to DISA
Send feedback or change requests to [email protected]
-
Schedule periodic compliance reviews and STIG updates
Plan recurring reviews and re-check controls after STIG updates.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.