Information
Auto Unlock allows an Apple Watch to automatically unlock an iPhone or Mac when in close proximity (not available for iPad). This feature allows the iPhone/Mac to be unlocked without the user entering the device passcode, which may lead to unauthorized users access to the iPhone/Mac and sensitive DOD data. This control is not applicable if the authorizing official (AO) has approved the use of Apple Watches.
SFR ID: FMT_MOF_EXT.1.2 #47
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
If the AO has not approved the use of Apple Watch with DOD-owned iPhones, configure the Apple iOS configuration profile to disable 'Allow auto unlock'.
The procedure for implementing this control will vary depending on the MDM/EMM used by the mobile service provider.
In the MDM console, set 'Allow auto unlock' to 'False'.
Item Details
Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION
References: 800-53|AC-6(10), 800-53|IA-2(1), 800-53|IA-2(3), CAT|II, CCI|CCI-000765, CCI|CCI-000767, CCI|CCI-002235, Rule-ID|SV-254641r1015679_rule, STIG-ID|AIOS-16-014800, Vuln-ID|V-254641
Control ID: 20fd34d35178e5cc1e435582c4fa8636aa12167f93534fe97ccd5f2a9bda7389