3.2.1.9 Ensure 'Allow network drive access in Files app' is set to 'Disabled'

Information

This recommendation pertains to preventing the Files app from accessing networking file shares.

Rationale:
The Files app provides a local file system and interface to network file shares for iOS and iPadOS devices. In environments with sensitive data and strict data loss prevention policies, disabling the use of network file shares with such devices may reduce the risk of data leakage.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. Open Apple Configurator.
2. Open the Configuration Profile.
3. In the left windowpane, click on the Restrictions tab.
4. In the right windowpane, under the tab Functionality, uncheck the checkbox for Allow network drive access in Files app.
5. Deploy the Configuration Profile.

Impact:
End-users must configure a password for the encrypted backup; the complexity of which is not managed.

See Also

https://workbench.cisecurity.org/files/2141

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION

References: 800-53|CA-7, CSCv7|13.3

Plugin: MDM

Control ID: 5bc2814cafcfc26199b72094e0ac1275b94d779eb052992bc2972817467f7ff5