Skip to content

Apple iOS/iPadOS 17 MDFPP 3.3 BYOAD Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • PP-MDF-333300

    Group
  • Apple iOS/iPadOS 17 must be configured to [selection: wipe protected data, wipe sensitive data] upon unenrollment from MDM.

    When a mobile device is no longer going to be managed by MDM technologies, its protected/sensitive data must be sanitized because it will no longer be protected by the MDM software, putting it at m...
    Rule Medium Severity
  • PP-MDF-333310

    Group
  • PP-MDF-993300

    Group
  • Apple iOS/iPadOS 17 must require a valid password be successfully entered before the mobile device data is unencrypted.

    Passwords provide a form of access control that prevents unauthorized individuals from accessing computing resources and sensitive data. Passwords may also be a source of entropy for generation of ...
    Rule High Severity
  • PP-MDF-993300

    Group
  • Apple iOS/iPadOS 17 must implement the management setting: Encrypt backups/Encrypt local backup.

    If iCloud backups are not encrypted, this could lead to the unauthorized disclosure of DOD sensitive information if non-DOD personnel are able to access that machine. Forcing the backup to be encry...
    Rule Medium Severity
  • PP-MDF-993300

    Group
  • Apple iOS/iPadOS 17 must implement the management setting: require the user to enter a password when connecting to an AirPlay-enabled device.

    When a user is allowed to use AirPlay without a password, it may mistakenly associate the iPhone and iPad with an AirPlay-enabled device other than the one intended (i.e., by choosing the wrong one...
    Rule Low Severity
  • PP-MDF-993300

    Group
  • Apple iOS/iPadOS 17 must implement the management setting: require passcode for incoming Airplay connection requests.

    When an incoming AirPlay request is allowed without a password, it may mistakenly associate the iPhone and iPad with an AirPlay-enabled device other than the one intended (i.e., by choosing the wro...
    Rule Low Severity
  • PP-MDF-993300

    Group
  • PP-MDF-993300

    Group
  • Apple iOS/iPadOS 17 must implement the management setting: Treat AirDrop as an unmanaged destination.

    AirDrop is a way to send contact information or photos to other users with AirDrop enabled. This feature enables a possible attack vector for adversaries to exploit. Once the attacker has gained ac...
    Rule Medium Severity
  • PP-MDF-993300

    Group
  • Apple iOS/iPadOS 17 must implement the management setting: force Apple Watch wrist detection.

    Because Apple Watch is a personal device, it is key that any sensitive DOD data displayed on the Apple Watch cannot be viewed when the watch is not in the immediate possession of the user. This con...
    Rule Low Severity
  • PP-MDF-993300

    Group
  • Apple iOS/iPadOS 17 users must complete required training.

    The security posture on iOS devices requires the device user to configure several required policy rules on their device. User-Based Enforcement (UBE) is required for these controls. In addition, if...
    Rule Medium Severity
  • PP-MDF-993300

    Group
  • A managed photo app must be used to take and store work-related photos.

    The iOS Photos app is unmanaged and may sync photos with a device user's personal iCloud account. Therefore, work-related photos must not be taken via the iOS camera app or stored in the Photos app...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules