Ensure 'Allow USB accessories while the device is locked' is set to 'Disabled'


This recommendation pertains to allowing USB devices to communicate with a locked device.

Physical attacks against iOS devices have been developed that exploit the trust of physically connected accessories. This has lead to proof of concept data extraction and even commercially available hardware to perform the attacks. By requiring the device to be unlocked to remove data, this control reduces the probability of a successful data exfiltration.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.


1. Open Apple Configurator.
2. Open the Configuration Profile.
3. In the left windowpane, click on the Restrictions tab.
4. In the right windowpane, under the tab Functionality, uncheck the checkbox for Allow USB accessories while the device is locked.
5. Deploy the Configuration Profile.

An end-user will not be to connected a USB accessory while the device is locked.

See Also


Item Details


References: 800-53|CM-7b.

Plugin: MDM

Control ID: 1d7d7799448ff800162de36781ebac398adf1cbc30f3c8e3000fbc1f408490f5