AIOS-26-016200 - Apple iOS/iPadOS 26 must disable the use voice assistant (Show user-generated content in Siri) unless required to meet Section 508 compliance requirements - Show user-generated content in Siri unless required to meet Section 508 compliance requirements.

Information

The use of voice assistants could expose sensitive DOD data to cloud-based servers during the processing of assistant requests.

SFR ID: FMT_MOF_EXT.1.2 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a configuration profile to disable 'Show user-generated content in Siri', unless required to meet Section 508 compliance requirements. This is a supervised-only control.

Note: This control may not be configurable by some MDM products when 'Allow Siri' is disabled.

Configuration Profile Key: allowAssistantUserGeneratedContent

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_iOS-iPadOS_26_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-278834r1151202_rule, STIG-ID|AIOS-26-016200, Vuln-ID|V-278834

Plugin: MDM

Control ID: 12b3fe1d2ecd07f4d9940db40a5ef0be691187cde49eaf52faf1005459cc4f5b