Skip to content

Apple iOS/iPadOS 16 must require a valid password be successfully entered before the mobile device data is unencrypted.

An XCCDF Rule

Description

Passwords provide a form of access control that prevents unauthorized individuals from accessing computing resources and sensitive data. Passwords may also be a source of entropy for generation of key encryption or data encryption keys. If a password is not required to access data, this data is accessible to any adversary who obtains physical possession of the device. Requiring that a password be successfully entered before the mobile device data is unencrypted mitigates this risk. Note: MDF PP v2.0 requires a Password Authentication Factor and requires management of its length and complexity. It leaves open whether the existence of a password is subject to management. This requirement addresses the configuration to require a password, which is critical to the cybersecurity posture of the device. SFR ID: FIA_UAU_EXT.1.1

ID
SV-254606r959010_rule
Version
AIOS-16-010400
Severity
High
References
Updated

Remediation Templates

A Manual Procedure

Install a configuration profile to require a password to unlock the device.