The foundation of good security practices start in your organization.

Create a security and privacy team

Create a dedicated security and privacy team and establish a leader for this organization.

Build verification process

Evaluate gaps in your existing internal build verification and approval processes.

Source code change tracking

Monitor for unintentional modifications of source code or third-party apps / binaries / SDKs.

Validate source code integrity and pedigree

Inspect and validate source code supplied by an original device manufacturer (ODM), Over-the-air update (OTA), or carrier.

Incident response

Android believes in the power of a strong security community to help find issues. You should create and publicize a way for external parties to contact you about device-specific security issues.