Apple iOS/iPadOS 18 Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
Apple iOS/iPadOS 18 must implement the management setting: encrypt backups/Encrypt local backup.
If iCloud backups are not encrypted, this could lead to the unauthorized disclosure of DOD sensitive information if non-DOD personnel are able to access that machine. Forcing the backup to be encry...Rule Medium Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: not allow use of Handoff.
Handoff permits a user of an iPhone and iPad to transition user activities from one device to another. Handoff passes sufficient information between the devices to describe the activity, but app da...Rule Low Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: not allow use of iPhone widgets on Mac.
iPhone widgets on Mac use Handoff. Handoff permits a user of an iPhone and iPad to transition user activities from one device to another. Handoff passes sufficient information between the devices t...Rule Low Severity -
PP-MDF-993300
Group -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: require passcode for incoming Airplay connection requests.
When an incoming AirPlay request is allowed without a password, it may mistakenly associate the iPhone and iPad with an AirPlay-enabled device other than the one intended (i.e., by choosing the wro...Rule Low Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: disable Allow MailDrop.
MailDrop allows users to send large attachments (up to 5 GB) via iCloud. Storing data with a non-DOD cloud provider may leave the data vulnerable to breach. Disabling non-DOD cloud services mitigat...Rule Medium Severity -
PP-MDF-993300
Group -
iPhone and iPad must have the latest available iOS/iPadOS operating system installed.
Required security features are not available in earlier OS versions. In addition, earlier versions may have known vulnerabilities. SFRID: FMT_SMF.1.1 #47Rule High Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: use SSL for Exchange ActiveSync.
Exchange email messages are a form of data in transit and thus are vulnerable to eavesdropping and man-in-the-middle attacks. Secure Sockets Layer (SSL), also referred to as Transport Layer Securit...Rule Medium Severity -
PP-MDF-993300
Group -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: treat AirDrop as an unmanaged destination.
AirDrop is a way to send contact information or photos to other users with AirDrop enabled. This feature enables a possible attack vector for adversaries to exploit. Once the attacker has gained ac...Rule Medium Severity -
PP-MDF-993300
Group -
PP-MDF-993300
Group -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: force Apple Watch wrist detection.
Because Apple Watch is a personal device, it is key that any sensitive DOD data displayed on the Apple Watch cannot be viewed when the watch is not in the immediate possession of the user. This con...Rule Low Severity -
PP-MDF-993300
Group -
PP-MDF-993300
Group -
A managed photo app must be used to take and store work-related photos.
The iOS Photos app is unmanaged and may sync photos with a device or user's personal iCloud account. Therefore, work-related photos must not be taken via the iOS camera app or stored in the Photos ...Rule Medium Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: enable USB Restricted Mode.
The USB port on an iOS device can be used to access data on the device. The required settings ensure the Apple device password is entered before a previously trusted USB accessory can connect to th...Rule Medium Severity -
PP-MDF-993300
Group -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must not allow unmanaged apps to read contacts from managed contacts accounts.
Managed apps have been approved for the handling of DOD sensitive information. Unmanaged apps are provided for productivity and morale purposes but are not approved to handle DOD sensitive informat...Rule Low Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: disable AirDrop.
AirDrop is a way to send contact information or photos to other users with this same feature enabled. This feature enables a possible attack vector for adversaries to exploit. Once the attacker has...Rule Medium Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: disable paired Apple Watch.
Authorizing official (AO) approval is required before an Apple Watch (DOD-owned or personally owned) can be paired with a DOD-owned iPhone to ensure the AO has evaluated the risk in having sensitiv...Rule Medium Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must implement the management setting: approved Apple Watches must be managed by an MDM.
Authorizing official (AO) approval is required before an Apple Watch (DOD-owned or personally owned) can be paired with a DOD-owned iPhone to ensure the AO has evaluated the risk in having sensitiv...Rule Medium Severity -
PP-MDF-993300
Group -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must disable "Allow setting up new nearby devices".
This control allows Apple device users to request passwords from nearby devices. This could lead to a compromise of the device password with an unauthorized person or device. DOD Apple device passw...Rule Medium Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must disable password proximity requests.
This control allows one Apple device to be notified to share its password with a nearby device. This could lead to a compromise of the device password with an unauthorized person or device. DOD App...Rule Medium Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must disable password sharing.
This control allows sharing passwords between Apple devices using AirDrop. This could lead to a compromise of the device password with an unauthorized person or device. DOD Apple device passwords m...Rule Medium Severity -
PP-MDF-993300
Group -
Apple iOS/iPadOS 18 must disable "Find My Friends" in the "Find My" app.
This control does not share a DOD user's location but encourages location sharing between DOD mobile device users, which can lead to operational security (OPSEC) risks. Sharing the location of a DO...Rule Low Severity -
PP-MDF-993300
Group -
The Apple iOS/iPadOS 18 must be supervised by the MDM.
When an iOS/iPadOS is not supervised, the DOD mobile service provider cannot control when new iOS/iPadOS updates are installed on site-managed devices. Most updates should be installed immediately ...Rule Medium Severity -
PP-MDF-333240
Group -
PP-MDF-993300
Group -
PP-MDF-993300
Group -
Apple iOS must implement the management setting: not allow a user to remove Apple iOS configuration profiles that enforce DOD security requirements.
Configuration profiles define security policies on Apple iOS devices. If a user is able to remove a configuration profile, the user can then change the configuration that had been enforced by that ...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.