2.2.1.4 Ensure 'Force encrypted backups' is set to 'Enabled'

Information

This recommendation pertains to encrypting iTunes backups of iOS and iPadOS devices.

Rationale:

Data that are stored securely on an iOS or iPadOS device may be trivially accessed from a local computer backup. Forcing the encryption of backups protects data from being compromised if the local host computer is compromised.

Impact:

End-users must configure a password for the encrypted backup; the complexity of which is not managed.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left windowpane, click on the Restrictions tab.

In the right windowpane, under the tab Functionality, check the checkbox for Force encrypted backups.

Deploy the Configuration Profile.

Additional Information:

This function does not apply to iCloud backups. iCloud backups are encrypted in transit and at rest by Apple.

See Also

https://workbench.cisecurity.org/files/3064