2.7.2 iCloud keychain

Information

The iCloud keychain is Apple's password manager that works with OS X and iOS. The capability allows users to store passwords in either iOS or OS X for use in Safari on both platforms and other iOS integrated applications. The most pervasive use is driven by iOS use rather than OS X. The passwords stored in an OS X keychain on an Enterprise managed computer could be stored in Apple's cloud and then be available on a personal computer using the same account. The stored passwords could be for organizational as well as personal accounts.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open System Preferences: iCloud and deselect Keychain if it is not approved in your organization

See Also

https://workbench.cisecurity.org/files/301