2.2.1.8 Ensure 'Allow documents from managed sources in unmanaged destinations' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This recommendation pertains to Apple's managed application implementation.

The terms 'managed' and 'unmanaged' refer to application classifications made through Managed Open In, a feature introduced in iOS 7. Managed Open In provides for data containerization. Institutionally-provisioned applications are designated as managed. Applications elected by the end user are designated as unmanaged.

Rationale:

Limiting data transfer from the managed institutional application space to the unmanaged user space may prevent data leakage.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Allow documents from managed sources in unmanaged destinations.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/17713