CIS Android 14 Enterprise Benchmark
Secure configuration guidelines for Android 14 enterprise-managed devices
v1.0.0 February 2025Overview
▶This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Android 14 Enterprise. Recommendations cover device lock and authentication, network configuration, application management, data protection, enterprise management, and developer/debug settings.
| Section | Area | Focus |
|---|---|---|
| 1 | Device Lock | Screen lock, biometrics |
| 2 | Network | Wi-Fi, VPN, Bluetooth |
| 3 | Applications | Installation, permissions |
| 4 | Data Protection | Encryption, backup |
| 5 | Enterprise | EMM, restrictions |
| 6 | Developer | Debug, updates |
Profile Definitions
▶| Profile | Description | Intended Use |
|---|---|---|
| L1 | Level 1 — Standard | Essential security for all Android 14 deployments; minimal performance impact. |
| L2 | Level 2 — Hardened | Advanced hardening for PCI-DSS, HIPAA, or high-security environments. |
1 — Device Lock & Authentication
▶1.1 Screen Lock
▶This recommendation ensures that Screen Lock Is Required on the Android 14 mobile device. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Android 14 mobile device may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
On the Android device, navigate to Settings and verify that Screen Lock Is Required. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Screen Lock Is Required. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Minimum PIN/Password Length Is 6 or More on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Minimum PIN/Password Length Is 6 or More. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Minimum PIN/Password Length Is 6 or More. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Auto-Lock Timeout Is Set to 2 Minutes or Less on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Auto-Lock Timeout Is Set to 2 Minutes or Less. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Auto-Lock Timeout Is Set to 2 Minutes or Less. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Maximum Failed Attempts Before Wipe Is Configured on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Maximum Failed Attempts Before Wipe Is Configured. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Maximum Failed Attempts Before Wipe Is Configured. For enterprise deployments, push the setting via EMM/MDM policy.
1.2 Biometric Authentication
▶This recommendation verifies that Biometric Unlock Is Configured on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Biometric Unlock Is Configured. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Biometric Unlock Is Configured. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation ensures that Face Unlock Requires Attention on the Android 14 mobile device. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Android 14 mobile device may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
On the Android device, navigate to Settings and verify that Face Unlock Requires Attention. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Face Unlock Requires Attention. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Smart Lock Is Disabled on the Android 14 mobile device. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Android 14 mobile device increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
On the Android device, navigate to Settings and verify that Smart Lock Is Disabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Smart Lock Is Disabled. For enterprise deployments, push the setting via EMM/MDM policy.
2 — Network Configuration
▶2.1 Wi-Fi Security
▶This recommendation verifies that Open Wi-Fi Auto-Connect Is Disabled on the Android 14 mobile device. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Android 14 mobile device increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
On the Android device, navigate to Settings and verify that Open Wi-Fi Auto-Connect Is Disabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Open Wi-Fi Auto-Connect Is Disabled. For enterprise deployments, push the setting via EMM/MDM policy.
This setting ensures that Wi-Fi Direct Is Controlled on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that Wi-Fi Direct Is Controlled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Wi-Fi Direct Is Controlled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Randomized MAC Address Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Randomized MAC Address Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Randomized MAC Address Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
2.2 Network Settings
▶This recommendation verifies that VPN Is Configured for Enterprise Use on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that VPN Is Configured for Enterprise Use. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure VPN Is Configured for Enterprise Use. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Always-On VPN Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Always-On VPN Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Always-On VPN Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Bluetooth Is Disabled When Not in Use on the Android 14 mobile device. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Android 14 mobile device increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
On the Android device, navigate to Settings and verify that Bluetooth Is Disabled When Not in Use. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Bluetooth Is Disabled When Not in Use. For enterprise deployments, push the setting via EMM/MDM policy.
This setting ensures that NFC Is Controlled on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that NFC Is Controlled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure NFC Is Controlled. For enterprise deployments, push the setting via EMM/MDM policy.
This setting ensures that Nearby Share Is Restricted on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that Nearby Share Is Restricted. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Nearby Share Is Restricted. For enterprise deployments, push the setting via EMM/MDM policy.
3 — Application Management
▶3.1 App Installation
▶This recommendation verifies that Unknown Sources Is Disabled on the Android 14 mobile device. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Android 14 mobile device increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
On the Android device, navigate to Settings and verify that Unknown Sources Is Disabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Unknown Sources Is Disabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Google Play Protect Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Google Play Protect Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Google Play Protect Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that App Verification Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that App Verification Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure App Verification Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
3.2 App Permissions
▶This setting ensures that Location Permissions Are Controlled per App on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that Location Permissions Are Controlled per App. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Location Permissions Are Controlled per App. For enterprise deployments, push the setting via EMM/MDM policy.
This setting ensures that Camera Access Is Controlled per App on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that Camera Access Is Controlled per App. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Camera Access Is Controlled per App. For enterprise deployments, push the setting via EMM/MDM policy.
This setting ensures that Microphone Access Is Controlled per App on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that Microphone Access Is Controlled per App. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Microphone Access Is Controlled per App. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Unused App Permissions Are Auto-Revoked on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Unused App Permissions Are Auto-Revoked. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Unused App Permissions Are Auto-Revoked. For enterprise deployments, push the setting via EMM/MDM policy.
4 — Data Protection
▶4.1 Encryption & Privacy
▶This recommendation verifies that Device Encryption Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Device Encryption Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Device Encryption Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Lock Screen Notifications Are Hidden on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Lock Screen Notifications Are Hidden. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Lock Screen Notifications Are Hidden. For enterprise deployments, push the setting via EMM/MDM policy.
This setting ensures that Clipboard Access Is Controlled on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that Clipboard Access Is Controlled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Clipboard Access Is Controlled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Private Space Is Configured on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Private Space Is Configured. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Private Space Is Configured. For enterprise deployments, push the setting via EMM/MDM policy.
4.2 Backup & Storage
▶This recommendation verifies that Backups Are Encrypted on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Backups Are Encrypted. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Backups Are Encrypted. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that USB Debugging Is Disabled on the Android 14 mobile device. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Android 14 mobile device increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
On the Android device, navigate to Settings and verify that USB Debugging Is Disabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure USB Debugging Is Disabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that SD Card Encryption Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that SD Card Encryption Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure SD Card Encryption Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
5 — Enterprise Management
▶5.1 EMM/MDM Configuration
▶This recommendation verifies that Device Is Enrolled in EMM on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Device Is Enrolled in EMM. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Device Is Enrolled in EMM. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Work Profile Is Configured on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Work Profile Is Configured. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Work Profile Is Configured. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Remote Wipe Capability Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Remote Wipe Capability Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Remote Wipe Capability Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation ensures that Compliance Policies Are Enforced on the Android 14 mobile device. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Android 14 mobile device may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
On the Android device, navigate to Settings and verify that Compliance Policies Are Enforced. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Compliance Policies Are Enforced. For enterprise deployments, push the setting via EMM/MDM policy.
5.2 Enterprise Restrictions
▶This recommendation verifies that Factory Reset Protection Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Factory Reset Protection Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Factory Reset Protection Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
This setting ensures that Screen Capture Is Controlled on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that Screen Capture Is Controlled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Screen Capture Is Controlled. For enterprise deployments, push the setting via EMM/MDM policy.
This setting ensures that Cross-Profile Data Sharing Is Restricted on the Android 14 mobile device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Android 14 mobile device is essential for defense in depth.
On the Android device, navigate to Settings and verify that Cross-Profile Data Sharing Is Restricted. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Cross-Profile Data Sharing Is Restricted. For enterprise deployments, push the setting via EMM/MDM policy.
6 — Developer & Debug Settings
▶6.1 Developer Options
▶This recommendation verifies that Developer Options Are Disabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Developer Options Are Disabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Developer Options Are Disabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that ADB Debugging Is Disabled on the Android 14 mobile device. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Android 14 mobile device increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
On the Android device, navigate to Settings and verify that ADB Debugging Is Disabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure ADB Debugging Is Disabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that OEM Unlocking Is Disabled on the Android 14 mobile device. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Android 14 mobile device increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
On the Android device, navigate to Settings and verify that OEM Unlocking Is Disabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure OEM Unlocking Is Disabled. For enterprise deployments, push the setting via EMM/MDM policy.
6.2 System Updates
▶This recommendation verifies that Auto-Update Is Enabled for System on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Auto-Update Is Enabled for System. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Auto-Update Is Enabled for System. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Security Patch Level Is Current on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Security Patch Level Is Current. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Security Patch Level Is Current. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that Google Play System Updates Are Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that Google Play System Updates Are Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure Google Play System Updates Are Enabled. For enterprise deployments, push the setting via EMM/MDM policy.
This recommendation verifies that App Auto-Update Is Enabled on the Android 14 mobile device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Android 14 mobile device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
On the Android device, navigate to Settings and verify that App Auto-Update Is Enabled. For EMM-managed devices, confirm the policy enforces this setting.
Navigate to Settings on the Android device and configure App Auto-Update Is Enabled. For enterprise deployments, push the setting via EMM/MDM policy.