The LG Android 5.0 platform must not allow the user to modify Owner Info on the device screen.

From LG Android 5.x Interim Security Configuration Guide

Part of PP-MDF-991000

Associated with: CCI-000366

SV-73275r1_rule The LG Android 5.0 platform must not allow the user to modify Owner Info on the device screen.

Vulnerability discussion

The Owner Info screen may contain required information, including a phone number to call if a device is lost, or the DoD Warning Banner. The ability of the device user to modify the Set Owner Info screen needs to be disabled so that required info is always displayed on the locked screen.SFR ID: FMT_MOF.1.1(2) #11

Check content

Note: This requirement is Not Applicable if the site has not configured the optional "Set Owner Info" configuration setting. This validation procedure is performed on both the MDM Administration Console and the LG Android device. Check whether the appropriate setting is configured on the MDM Administration Console: 1. Ask the MDM administrator to display the "Disallow Owner Info" setting in the MDM console. 2. Verify the setting is enabled. On the LG Android platform device: 1. Go to lock screen. 2. Show owner info on the lock screen. 3. Navigate to the password entry screen: Settings >> Lockscreen >> Contact info for lost phone 4. Verify the Owner info is displayed but the user cannot change it. If the "Disallow Owner Info" setting is not enabled, or if the user is able to change the owner info text on the device, this is a finding.

Fix text

Configure the mobile device to disallow a user to change owner info displayed on the locked screen. On the MDM Administration Console, enable the "Disallow Owner Info" setting.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer