Samsung Android 15 BYOAD STIG Checklist
24 items · Security · Medium difficulty · 2 hours
Secure Samsung Android 15 devices for BYOAD use with a practical STIG checklist.
-
Verify device OS is Android 15.0
Confirm exact build and security patch level before applying STIG settings.
-
Enroll device in an approved MDM/EMM
Use an enterprise-approved management platform to enforce policies and reporting.
-
Configure and enable NIAP-certified work profile for data separation
Enable certified work profile to separate CUI and personal data per MDFPP.
-
Verify work profile isolation between work and personal data
Test that work apps cannot access personal storage and vice versa.
-
Assign and manage enterprise apps inside the work profile
Deliver apps through the managed store and restrict personal installation.
-
Configure data sharing and clipboard restrictions for the work profile
Limit copy/paste and data sharing between work and personal profiles.
-
Enable device encryption
Ensure file-based or full-disk encryption is active for all storage.
-
Set a strong screen lock (PIN/password with timeout and lockout)
Enforce complexity, auto-lock timeout, and failed-attempt lockout.
-
Enable biometric authentication with PIN fallback
Allow biometrics only with a secure fallback and enterprise policy control.
-
Enforce automatic OS and security updates
Configure updates to install automatically or notify users via MDM.
-
Disable developer options and USB debugging
Prevent device tampering and unauthorized data extraction.
-
Disable installation from unknown sources; allow only managed/Play Store
Restrict sideloading to reduce malware risk; use managed Play store for apps.
-
Enable verified boot / secure boot attestation
Verify device integrity at boot to detect tampering or compromised firmware.
-
Install required enterprise apps and updates from the managed store
Ensure work-related apps are current and delivered via enterprise channels.
-
Restrict app permissions to least privilege and review periodically
Audit and revoke excessive permissions for work-profile apps.
-
Configure per-app VPN or enforce enterprise VPN for work traffic
Route work data through approved VPNs for confidentiality and monitoring.
-
Enable remote wipe, selective wipe for work profile, and device locate
Verify remote actions work from the MDM and test selective wipe behavior.
-
Configure backup controls for the work profile and disallow CUI export
Prevent backups from exporting controlled data to unmanaged services.
-
Disable or restrict Bluetooth and NFC when not required
Turn off radios by policy or require user action to reduce attack surface.
-
Enable and forward audit logs to enterprise logging or SIEM
Collect device events for forensic and compliance purposes.
-
Perform a STIG compliance scan and remediate findings
Run automated checks against the STIG and address deficiencies.
-
Document approved exceptions and retain compliance records
Record any deviations with justification, approval, and retention schedule.
-
Provide BYOAD user training and require policy acknowledgement
Train users on handling CUI, app separation, and device hygiene; capture consent.
-
Schedule periodic re-checks and firmware update reviews
Plan recurring scans, audits, and update cycles to maintain compliance.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.