Samsung Android 15 with Knox 3.x STIG Compliance
17 items · Security · Medium difficulty · 2 hours
Practical STIG tasks for deploying and securing Samsung Android 15 devices.
-
Use Android Enterprise (AE) deployment for all Samsung Android 15 devices
AE is the supported management method; do not rely on legacy Device Admin.
-
Disable Device Admin (DA) legacy management
Migrate any DA-managed devices to AE to meet STIG scope.
-
Restrict deployments to COPE and COBO device use cases
Exclude BYOD and CYOD from this STIG scope.
-
Obtain Authorizing Official (AO) approval for personal app installs
Require AO authorization before allowing user personal apps on COPE devices.
-
Configure biometric authentication policies
Define allowed biometric methods and documentation requirements.
-
Allow fingerprint biometric for device and work profile unlock
Fingerprint is approved with AO oversight and Common Criteria review.
-
Disable facial recognition and trust agents
Other Samsung biometric methods are not approved by this STIG.
-
Document AO approval for fingerprint use
Record approval and any restrictions for audit purposes.
-
Enroll corporate devices via Knox Mobile Enrollment (KME) or AE zero-touch
Prefer KME for bulk Samsung deployments; zero-touch is an alternative.
-
Apply Android Enterprise policies to meet baseline STIG requirements
Use AE policies as the baseline controls mandated by the STIG.
-
Use Knox policies to augment AE policies where AE cannot enforce controls
Deploy Knox-only controls only when AE lacks equivalent capability.
-
Configure Wi‑Fi per Network Infrastructure STIG before allowing network connection
Ensure wireless infrastructure complies with the Network STIG first.
-
Restrict personal space and work profile data per STIG supplemental docs
Follow Section 6.2 of the STIG Supplemental for personal space config.
-
Verify device Common Criteria evaluation status for biometric methods
Confirm fingerprint evaluation status during platform reviews.
-
Maintain enrollment, policy, and compliance documentation for each device
Keep records for audits and incident response.
-
Report STIG comments or change requests to DISA at [email protected]
Send proposed revisions to DISA for coordination and updates.
-
Ensure ongoing compliance with DoDI 8500.01 and review STIG updates regularly
Monitor updates and revalidate settings when the STIG revises.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.