Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 must implement the management setting: not share location data through iCloud.

    Sharing of location data is an operational security (OPSEC) risk because it potentially allows an adversary to determine a DoD user's location, movements, and patterns in those movements over time....
    Rule Medium Severity
  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 must implement the management setting: force Apple Watch wrist detection.

    Because Apple Watch is a personal device, it is key that any sensitive DoD data displayed on the Apple Watch cannot be viewed when the watch is not in the immediate possession of the user. This con...
    Rule Low Severity
  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 users must complete required training.

    The security posture on iOS devices requires the device user to configure several required policy rules on their device. User Based Enforcement (UBE) is required for these controls. In addition, if...
    Rule Medium Severity
  • PP-MDF-990000

    Group
  • A managed photo app must be used to take and store work-related photos.

    The iOS Photos app is unmanaged and may sync photos with a device user's personal iCloud account. Therefore, work-related photos must not be taken via the iOS camera app or stored in the Photos app...
    Rule Medium Severity
  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 must implement the management setting: enable USB Restricted Mode.

    The USB lightning port on an iOS device can be used to access data on the device. The required settings ensure the Apple device password is entered before a previously trusted USB accessory can con...
    Rule Medium Severity
  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 must not allow managed apps to write contacts to unmanaged contacts accounts.

    Managed apps have been approved for the handling of DoD sensitive information. Unmanaged apps are provided for productivity and morale purposes but are not approved to handle DoD sensitive informat...
    Rule Low Severity
  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 must not allow unmanaged apps to read contacts from managed contacts accounts.

    Managed apps have been approved for the handling of DoD sensitive information. Unmanaged apps are provided for productivity and morale purposes but are not approved to handle DoD sensitive informat...
    Rule Low Severity
  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 must implement the management setting: disable AirDrop.

    AirDrop is a way to send contact information or photos to other users with this same feature enabled. This feature enables a possible attack vector for adversaries to exploit. Once the attacker has...
    Rule Low Severity
  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 must implement the management setting: disable paired Apple Watch.

    Authorizing Official (AO) approval is required before an Apple Watch (DoD-owned or personally owned) can be paired with a DoD-owned iPhone to ensure the AO has evaluated the risk in having sensitiv...
    Rule Medium Severity
  • PP-MDF-990000

    Group
  • Apple iOS/iPadOS 15 must disable Password AutoFill in browsers and applications.

    The AutoFill functionality in browsers and applications allows the user to complete a form that contains sensitive information, such as PII, without previous knowledge of the information. By allowi...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules