DEVICE-006: Jailbroken/Rooted Device Policy

Platform
Google Workspace
Category
Device & Endpoint Management
Severity
High
Zero Trust pillar
Devices (weight 3)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Jailbroken (iOS) or rooted (Android) devices bypass OS-level security controls and should be blocked from accessing organizational data

Recommended value

Jailbroken/rooted devices blocked from organizational data access

Remediation

Admin Console > Devices > Mobile & endpoints > Settings > Universal settings > Compromised devices > Block jailbroken/rooted devices

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for DEVICE-006
ScenarioExpected verdict
always-warnWARN

Framework mappings

NIST SP 800-53
SI-7, AC-19
CIS Benchmark
6.6
MITRE ATT&CK
T1398