Skip to content

Apple iOS-iPadOS 16 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • PP-MDF-321090

    Group
  • Apple iOS/iPadOS 16 must allow the Administrator (MDM) to perform the following management function: enable/disable VPN protection across the device and [selection: other methods].

    The system administrator must have the capability to configure VPN access to meet organization-specific policies based on mission needs. Otherwise, a user could inadvertently or maliciously set up ...
    Rule Low Severity
  • PP-MDF-321280

    Group
  • Apple iOS/iPadOS 16 must not allow backup to remote systems (iCloud).

    If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploi...
    Rule Medium Severity
  • PP-MDF-321290

    Group
  • Apple iOS/iPadOS 16 must not allow backup to remote systems (iCloud document and data synchronization).

    If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploi...
    Rule Medium Severity
  • PP-MDF-321290

    Group
  • PP-MDF-321290

    Group
  • Apple iOS/iPadOS 16 must not allow backup to remote systems (My Photo Stream).

    If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploi...
    Rule Medium Severity
  • PP-MDF-321290

    Group
  • Apple iOS/iPadOS 16 must not allow backup to remote systems (iCloud Photo Sharing, also known as Shared Photo Streams).

    If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploi...
    Rule Medium Severity
  • PP-MDF-321290

    Group
  • Apple iOS/iPadOS 16 must not allow backup to remote systems (managed applications data stored in iCloud).

    If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploi...
    Rule Medium Severity
  • PP-MDF-321290

    Group
  • Apple iOS/iPadOS 16 must not allow backup to remote systems (enterprise books).

    If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploi...
    Rule Medium Severity
  • PP-MDF-321400

    Group
  • Apple iOS/iPadOS 16 must [selection: wipe protected data, wipe sensitive data] upon unenrollment from MDM.

    When a mobile device is no longer going to be managed by MDM technologies, its protected/sensitive data must be sanitized because it will no longer be protected by the MDM software, putting it at m...
    Rule Medium Severity
  • PP-MDF-321410

    Group
  • PP-MDF-323024

    Group
  • PP-MDF-323025

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules