MobileIron - DISA Apple iOS 11 v1r4

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: MobileIron - DISA Apple iOS 11 v1r4

Updated: 4/9/2019

Authority: DISA STIG

Plugin: MDM

Revision: 1.0

Estimated Item Count: 42

Audit Items

DescriptionCategories
AIOS-11-000100 - Apple iOS must enforce a minimum password length of six characters.

IDENTIFICATION AND AUTHENTICATION

AIOS-11-000200 - Apple iOS must not allow passwords that include more than two repeating or sequential characters.

IDENTIFICATION AND AUTHENTICATION

AIOS-11-000300 - Apple iOS must lock the display after 15 minutes (or less) of inactivity.

ACCESS CONTROL

AIOS-11-000400 - Apple iOS must not allow more than 10 consecutive failed authentication attempts.

ACCESS CONTROL

AIOS-11-000900 - Apple iOS must be configured to enforce an application installation policy specifying authorized application repositories.
AIOS-11-001200 - Apple iOS must not include applications with the following characteristics: Siri when the device is locked.
AIOS-11-001300 - Apple iOS must not include applications with the following characteristics: Voice dialing application if when MD is locked.
AIOS-11-001700 - Apple iOS must not display notifications when the device is locked.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-001800 - Apple iOS must not display notifications (calendar information) when the device is locked.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-003500 - Apple iOS must be configured to display DoD advisory warning message at start-up or each time the user unlocks the device.
AIOS-11-003900 - Apple iOS must not allow backup of managed app data to locally connected systems.
AIOS-11-004100 - Apple iOS must not allow backup to remote systems (iCloud).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-004200 - Apple iOS must not allow backup to remote systems (iCloud document and data synchronization).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-004300 - Apple iOS must not allow backup to remote systems (iCloud Keychain).
AIOS-11-004400 - Apple iOS must not allow backup to remote systems (My Photo Stream).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-004500 - Apple iOS must not allow backup to remote systems (iCloud Photo Sharing, also known as Shared Photo Streams).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-004600 - Apple iOS must not allow backup to remote systems (managed applications data stored in iCloud).
AIOS-11-005210 - Apple iOS must not allow non-DoD applications to access DoD data.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-005400 - Apple iOS must disable automatic transfer of diagnostic data to device other than an MDM service which device has enrolled.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-007200 - Apple iOS must implement the management setting: remove managed applications upon unenrollment from MDM.
AIOS-11-010800 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.

ACCESS CONTROL

AIOS-11-010900 - Apple iOS must implement the management setting: limit Ad Tracking.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-011000 - Apple iOS must implement the management setting: not allow automatic completion of Safari browser passcodes.

CONFIGURATION MANAGEMENT

AIOS-11-011100 - Apple iOS must implement the management setting: Encrypt iTunes backups.

ACCESS CONTROL

AIOS-11-011200 - Apple iOS must not allow backup to remote systems (enterprise books).
AIOS-11-011300 - Apple iOS must implement the management setting: not allow use of Handoff.
AIOS-11-011400 - Apple iOS must not allow backup to remote systems (managed applications data stored in iCloud).
AIOS-11-011500 - Apple iOS must implement the management setting: require a password when connecting to an AirPlay device the first time.
AIOS-11-011600 - Apple iOS must implement the management setting: Disable Allow MailDrop.
AIOS-11-011700 - Apple iOS must implement the management setting: Disable Allow iCloud Photo Library.
AIOS-11-011800 - Apple iOS device must have the latest available iOS operating system installed.
AIOS-11-011900 - Apple iOS must implement the management setting: use SSL for Exchange ActiveSync.

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-11-012000 - Apple iOS must implement the management setting: not allow ActiveSync messages to be forwarded or moved to other accounts.

ACCESS CONTROL

AIOS-11-012100 - Apple iOS must implement the management setting: Treat Airdrop as an unmanaged destination.
AIOS-11-012200 - Apple iOS must implement the management setting: not have any Family Members in Family Sharing.
AIOS-11-012300 - Apple iOS must implement the management setting: not share location data through iCloud.
AIOS-11-012400 - Apple iOS must implement the management setting: not allow a user to remove DoD security configuration profiles.

ACCESS CONTROL

AIOS-11-012500 - Apple iOS must implement the management setting: force Apple Watch wrist detection.
AIOS-11-012700 - Apple iOS users must complete required training.
AIOS-11-012800 - If an unmanaged third-party VPN client is installed on the iOS device, it must not be configured with a DoD VPN profile.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-11-012900 - A managed photo app must be used to take and store work related photos.
AIOS-11-015000 - Only authorized versions of the Apple iOS must be used.