STIGUI
V-284742CAT II — Medium severitySV-284742r1240615_rule

Google Android 17 must implement the management setting: Disable Camera.

Rule version GOOG-17-010700 · STIG v1 · 2026-07-09

Discussion

Authorizing official (AO) approval is required before the mobile device camera can be enabled for a specific user or group of users, based on a risk assessment of the operational environment. Camera use may lead to the exposure of sensitive DoW information in some operational environments.

SFR ID: FMT_MOF_EXT.1.2 #47

Check

Determine if the site AO has approved the use of device cameras. Look for a document showing approval for a specific user or group of users. If not approved, review the configuration settings to confirm "Allow Camera" is disabled. If approved, this requirement is not applicable. Review the configuration settings to confirm the device camera has been disabled.

This check procedure is performed on the device management tool and the Google Android 17 device.

On the MDM console:

COBO and COPE:

1. Open Camera. 2. Verify that the "Disable camera" setting is disabled.

On the managed Google Android 17 device:

COBO and COPE:

Verify that the camera cannot be used on the mobile device.

If the device camera has not been disabled, this is a finding.

Fix

If the AO has not approved the use of the Google device camera, configure Android 17 to disable the device camera.

On the MDM console:

COBO and COPE:

1. Open Camera. 2. Select "Disable camera".

Configuration API: cameraDisabled

Identifiers

Group ID
V-284742
Group title
PP-MDF-994000
Rule ID
SV-284742r1240615_rule
Check ID
C-89312r1239931_chk
Fix ID
F-89217r1239932_fix