AIOS-26-015100 - Apple iOS/iPadOS 26 must delete eSIM content when the device is erased.

Information

An eSIM may contain sensitive DOD data and must be wiped of data when the mobile device is wiped to protect sensitive data from exposure.

SFR ID: FMT_MOF_EXT.1.2 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a configuration profile to delete eSIM content when the device is erased.

Configuration Profile Key: forcePreserveESIMOnErase

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_iOS-iPadOS_26_V1R2_STIG.zip

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-6(3), CAT|II, CCI|CCI-001033, Rule-ID|SV-278826r1150725_rule, STIG-ID|AIOS-26-015100, Vuln-ID|V-278826

Plugin: MDM

Control ID: 9e08bff0bc0c150ed842e7c2e2a2a4b25d36839a3cfc62f9b830e69f4cd7550f