Zebra Android 14 STIG Checklist
18 items · Security · Hard difficulty · 2 hours
Secure corporate Zebra Android 14 devices with the official STIG baseline.
-
Download the Zebra Android 14 STIG baseline (XCCDF)
Obtain the Standalone XCCDF 1.1.4 STIG from DISA or your STIG repository.
-
Review STIG summary, scope, and in-scope use cases
Confirm COBO and COPE are in-scope; BYOD/BYOAD are excluded.
-
Inventory Zebra devices running Android 14
Identify device models, OS versions, and ownership type (COBO/COPE).
-
Enroll devices in enterprise mobility management (EMM)
Use corporate enrollment or device-owner mode for centralized control.
-
Enable device-owner / corporate mode in EMM
Set devices to managed/device-owner to enforce STIG policies.
-
Disable unmanaged app installs via EMM
Block sideloading and restrict installs to managed app store.
-
Configure managed app allowlist (managed Google Play or equivalent)
Allow only approved apps required for business functions.
-
Apply STIG configuration profiles to enrolled devices
Push STIG settings via EMM or import XCCDF to your management tool.
-
Require strong authentication and lock-screen policies
Enforce PIN/password length, complexity, timeout, and biometric rules.
-
Enable full-disk or file-based encryption
Ensure device storage is encrypted per Android 14 capabilities.
-
Enforce approved Wi‑Fi profiles and restrict direct enclave connections
Use enterprise Wi‑Fi configs and ensure network complies with Network STIG.
-
Disable ADB, developer options, and debugging features
Prevent device-level debugging that can bypass protections.
-
Block installation from unknown sources and sideloading
Restrict installs to managed channels only.
-
Enable logging, audit, and reporting for STIG controls
Activate device logs and central reporting to detect deviations.
-
Run compliance scans and generate STIG reports
Use EMM or STIG tools to evaluate settings and produce reports.
-
Review and remediate non-compliant findings
Address vulnerabilities, misconfigurations, and document fixes.
-
Document approved exceptions and AO approvals
Record Authorizing Official approvals for allowed deviations.
-
Schedule regular re-scans and STIG baseline updates
Plan periodic compliance checks and apply STIG revisions.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.