AIOS-18-016200 - Apple iOS/iPadOS 18 must disable the use of voice assistant (Show user-generated content in Siri) unless required to meet Section 508 compliance requirements.

Information

The use of voice assistants could expose sensitive DOD data to cloud-based servers during the processing of assistant requests.

SFR ID: FMT_MOF_EXT.1.2 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a configuration profile to disable 'Show user-generated content in Siri' unless required to meet Section 508 compliance requirements. This is a supervised-only control.

Note: This control may not be configurable by some MDM products when 'Allow Siri' is disabled.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_iOS-iPadOS_18_V1R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-276201r1115672_rule, STIG-ID|AIOS-18-016200, Vuln-ID|V-276201

Plugin: MDM

Control ID: e1844d1a49ae7513c76d626c451d2504e8090e00575c4dc4fc8368c176c00486