MobileIron - DISA Apple iOS 12 v2r1

Audit Details

Name: MobileIron - DISA Apple iOS 12 v2r1

Updated: 2/28/2023

Authority: DISA STIG

Plugin: MDM

Revision: 1.0

Estimated Item Count: 40

File Details

Filename: DISA_STIG_Apple_iOS_12_v2r1-MobileIron.audit

Size: 71.6 kB

MD5: a1aad09abe07c42115707edce6f3555a
SHA256: 46a422d4ccb58c04480d37c76440508aa6d0668f1ac7c46261a8ccb7dd4c0542

Audit Items

DescriptionCategories
AIOS-12-000100 - Apple iOS must be configured to enforce a minimum password length of six characters.

IDENTIFICATION AND AUTHENTICATION

AIOS-12-000200 - Apple iOS must be configured to not allow passwords that include more than two repeating or sequential characters.

CONFIGURATION MANAGEMENT

AIOS-12-000300 - Apple iOS must be configured to lock the display after 15 minutes (or less) of inactivity.

ACCESS CONTROL

AIOS-12-000400 - Apple iOS must be configured to not allow more than 10 consecutive failed authentication attempts.

ACCESS CONTROL

AIOS-12-001000 - Apple iOS must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: Apple App Store].

ACCESS CONTROL

AIOS-12-001300 - Apple iOS must not include applications with the following characteristics: Siri when the device is locked.

ACCESS CONTROL

AIOS-12-001400 - Apple iOS must not include applications with the following characteristics: Voice dialing application if available when MD is locked.

CONFIGURATION MANAGEMENT

AIOS-12-001800 - Apple iOS must not display notifications when the device is locked.

CONFIGURATION MANAGEMENT

AIOS-12-001900 - Apple iOS must not display notifications (calendar information) when the device is locked.

CONFIGURATION MANAGEMENT

AIOS-12-003600 - Apple iOS must be configured to display the DoD advisory warning message at start-up or each time the user unlocks the device.

CONFIGURATION MANAGEMENT

AIOS-12-004000 - Apple iOS must not allow backup of managed app data to locally connected systems.

CONFIGURATION MANAGEMENT

AIOS-12-004100 - Apple iOS must not allow backup to remote systems (iCloud).

CONFIGURATION MANAGEMENT

AIOS-12-004200 - Apple iOS must not allow backup to remote systems (iCloud document and data synchronization).

CONFIGURATION MANAGEMENT

AIOS-12-004300 - Apple iOS must not allow backup to remote systems (iCloud Keychain).

CONFIGURATION MANAGEMENT

AIOS-12-004400 - Apple iOS must not allow backup to remote systems (My Photo Stream).

CONFIGURATION MANAGEMENT

AIOS-12-004500 - Apple iOS must not allow backup to remote systems (iCloud Photo Sharing, also known as Shared Photo Streams).

CONFIGURATION MANAGEMENT

AIOS-12-004600 - Apple iOS must not allow backup to remote systems (managed applications data stored in iCloud).

CONFIGURATION MANAGEMENT

AIOS-12-004700 - Apple iOS must not allow backup to remote systems (enterprise books).

CONFIGURATION MANAGEMENT

AIOS-12-005600 - Apple iOS must not allow non-DoD applications to access DoD data.

CONFIGURATION MANAGEMENT

AIOS-12-010500 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-12-010600 - Apple iOS must implement the management setting: limit Ad Tracking.

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-12-010700 - Apple iOS must implement the management setting: not allow automatic completion of Safari browser passcodes.

CONFIGURATION MANAGEMENT

AIOS-12-010800 - Apple iOS must implement the management setting: Encrypt iTunes backups.

CONFIGURATION MANAGEMENT

AIOS-12-010900 - Apple iOS must implement the management setting: not allow use of Handoff.

CONFIGURATION MANAGEMENT

AIOS-12-011100 - Apple iOS must implement the management setting: require the user to enter a password when connecting to an AirPlay-enabled device for the first time.

ACCESS CONTROL

AIOS-12-011200 - Apple iOS must implement the management setting: Disable Allow MailDrop.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-12-011300 - Apple iOS must implement the management setting: Disable Allow Shared Albums.

CONFIGURATION MANAGEMENT

AIOS-12-011400 - Apple iOS device must have the latest available iOS operating system installed.

CONFIGURATION MANAGEMENT

AIOS-12-011500 - Apple iOS must implement the management setting: use SSL for Exchange ActiveSync.

IDENTIFICATION AND AUTHENTICATION

AIOS-12-011600 - Apple iOS must implement the management setting: not allow messages in an ActiveSync Exchange account to be forwarded or moved to other accounts in the Apple iOS Mail app.

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

AIOS-12-011700 - Apple iOS must implement the management setting: Treat Airdrop as an unmanaged destination.

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

AIOS-12-011800 - Apple iOS must implement the management setting: not have any Family Members in Family Sharing.

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

AIOS-12-011900 - Apple iOS must implement the management setting: not share location data through iCloud.

ACCESS CONTROL

AIOS-12-012100 - Apple iOS must implement the management setting: force Apple Watch wrist detection.

CONFIGURATION MANAGEMENT

AIOS-12-012200 - Apple iOS users must complete required training.

CONFIGURATION MANAGEMENT

AIOS-12-012300 - A managed photo app must be used to take and store work related photos.

ACCESS CONTROL

AIOS-12-012500 - Apple iOS must implement the management setting: enable USB Restricted Mode.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-12-012600 - Apple iOS must not allow managed apps to write contacts to unmanaged contacts accounts.

CONFIGURATION MANAGEMENT

AIOS-12-012700 - Apple iOS must not allow unmanaged apps to read contacts from managed contacts accounts.

CONFIGURATION MANAGEMENT

AIOS-12-999999 - All Apple iOS 12 installations must be removed.

CONFIGURATION MANAGEMENT