3.2.1.4 Ensure 'Allow iCloud backup' is set to 'Disabled'

Information

This recommendation pertains to allowing iCloud backup.

Rationale:

iCloud backups are encrypted in transit and at rest within Apple's infrastructure, but there is no protection against restoring a backup to an unmanaged device. This allows for data leakage.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left windowpane, click on the Restrictions tab.

In the right windowpane, under the tab Functionality, uncheck the checkbox for Allow iCloud backup.

Deploy the Configuration Profile.




Additional Information:

This recommendation is exclusively for institutionally owned devices. If an institution is relying on BYOD, those devices should not contain sensitive material necessary to protect at this level.

See Also

https://workbench.cisecurity.org/files/3064