4.4 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end-user owned devices

Information

This recommendation pertains to remote device locating, locking, and erasure by the end-user.

Rationale:

The ability to locate, lock, and erase a device remotely helps to mitigate impact of device theft and loss, and likelihood of loss.

This is only recommended for end-user owned devices. Institutionally owned devices should not be erasable by end-users.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the device:
1. Tap 'Settings'.
2. Tap '<_The Users Name_>' where Apple ID, iCloud, iTunes & App Store is displayed beneath.
3. Tap 'iCloud'.
4. Tap 'Find My iPhone'.
5. Verify Find My iPhone and Send Last Location are enabled.

Impact:

Evidence may be destroyed if an end-user performs an erase.

See Also

https://workbench.cisecurity.org/files/1806