Samsung Android 16 STIG Compliance Checklist (Y25M08)
17 items · Security · Medium difficulty · 4 hours
Implement Samsung Android 16 STIG controls for secure, managed Samsung devices.
-
Verify device OS version is Samsung Android 16
Confirm build number and patch level match STIG requirements.
-
Ensure device management uses Android Enterprise (AE)
AE is the supported management model for this STIG; do not use Device Admin.
-
Enroll devices using Knox Mobile Enrollment (KME) or AE zero-touch
Use bulk enrollment to ensure consistent, managed configurations.
-
Set up Knox Mobile Enrollment (KME) account and upload device list
Register devices in KME and bind to your EMM for COPE/COBO fleets.
-
Configure AE zero-touch enrollment in your EMM
Enable zero-touch provisioning if not using KME for bulk enrollment.
-
Configure STIG baseline security settings per Samsung Android 16 STIG
Apply the recommended security controls and configuration baselines.
-
Apply Knox policies where AE policies can't be used
Use Knox to augment AE and cover gaps in enterprise policy support.
-
Restrict deployment to COPE or COBO use cases
Do not enroll BYOD or CYOD devices under this STIG scope.
-
Configure the personal profile per STIG supplemental (Section 5.3.1)
Allow personal apps/data only with AO approval and imposed restrictions.
-
Authorize fingerprint biometric for device and workspace unlock (with AO approval)
Fingerprint is allowed with AO approval; other biometrics are not approved.
-
Disable unsupported biometric methods (facial recognition, trust agents)
Remove or disable non-approved biometric modalities per STIG.
-
Ensure Wi‑Fi networks comply with the Network Infrastructure STIG before connecting devices
Verify wireless infrastructure conforms to relevant STIG requirements.
-
Restrict installation of personal apps without AO approval for COPE devices
Implement controls to block or require approval before installs.
-
Review Common Criteria evaluation status for fingerprint biometric on Android 16
Confirm fingerprint evaluation results and re-review during CC updates.
-
Obtain the STIG and supplemental documents from DOD Cyber Exchange or public.cyber.mil
Download the latest STIG and supplemental guidance for reference.
-
Document configuration changes and submit comments/revisions to DISA via email
Send proposed revisions or questions to DISA at the published address.
-
Track compliance with DoDI 8500.01 and record testing/approvals
Maintain audit records and approval evidence for compliance reviews.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.