Catalina - Disable iCloud Document Sync

Information

The macOS built-in iCloud document synchronization service _MUST_ be disabled to prevent organizational data from being synchronized to personal or non-approved storage.

Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated document synchronization _MUST_ be controlled by an organization approved service.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.applicationaccess:
allowCloudDocumentSync:
False

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-20, 800-53|AC-20(1), 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-7(5)(b), 800-53|CM-7a., 800-53|SC-7(10), CCE|CCE-84734-3, CCI|CCI-000381, CCI|CCI-001774, STIG-ID|AOSX-15-002041, STIG-ID|AOSX-15-002049

Plugin: Unix

Control ID: 8b8cfe3cdd66e4e71b6e8dc074aef656efc5fc1b5d92d46e5c0b23abe4ad5004