AirWatch - DISA Apple iOS/iPadOS 13 v1r1

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: AirWatch - DISA Apple iOS/iPadOS 13 v1r1

Updated: 10/1/2021

Authority: DISA STIG

Plugin: MDM

Revision: 1.6

Estimated Item Count: 51

File Details

Filename: DISA_STIG_Apple_iOS_13_v1r1-AirWatch.audit

Size: 90.8 kB

MD5: a2b01a30faa6f62531ff8b5ef90dd5bd
SHA256: 2207d717fc353c678f9adcbac748ac57a8cde28f7c79113a95bfdcdd65153603

Audit Items

DescriptionCategories
AIOS-13-000100 - Apple iOS/iPadOS must be configured to enforce a minimum password length of six characters.

IDENTIFICATION AND AUTHENTICATION

AIOS-13-000200 - Apple iOS/iPadOS must be configured to not allow passwords that include more than two repeating or sequential characters.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-000300 - Apple iOS/iPadOS must be configured to lock the display after 15 minutes (or less) of inactivity.

ACCESS CONTROL

AIOS-13-000400 - Apple iOS/iPadOS must be configured to not allow more than 10 consecutive failed authentication attempts.

ACCESS CONTROL

AIOS-13-000800 - If a third-party VPN client is installed on the iOS/iPadOS device, it must not be configured with a DoD VPN profile.
AIOS-13-001000 - Apple iOS must be configured to enforce an application installation policy by specifying an authorized application repo.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-001300 - Apple iOS/iPadOS must not include applications with the following: access to Siri when the device is locked.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-001400 - Apple iOS/iPadOS must not include applications with the following: Voice dialing application if available when MD locked.
AIOS-13-001800 - Apple iOS/iPadOS must not display notifications when the device is locked.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-001900 - Apple iOS/iPadOS must not display notifications (calendar information) when the device is locked.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-003600 - Apple iOS/iPadOS must be configured to display the DoD advisory warning message at start-up.
AIOS-13-004000 - Apple iOS/iPadOS must not allow backup of managed app data to locally connected systems.
AIOS-13-004100 - Apple iOS/iPadOS must not allow backup to remote systems (iCloud).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-004200 - Apple iOS/iPadOS must not allow backup to remote systems (iCloud document and data synchronization).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-004300 - Apple iOS/iPadOS must not allow backup to remote systems (iCloud Keychain).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-004400 - Apple iOS/iPadOS must not allow backup to remote systems (My Photo Stream).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-004500 - Apple iOS/iPadOS must not allow backup to remote systems (iCloud Photo Sharing, also known as Shared Photo Streams).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-004600 - Apple iOS/iPadOS must not allow backup to remote systems (managed applications data stored in iCloud).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-004700 - Apple iOS/iPadOS must not allow backup to remote systems (enterprise books).

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-005600 - Apple iOS/iPadOS must not allow non-DoD applications to access DoD data.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-005800 - Apple iOS/iPadOS must be configured to disable transfer of diagnostic data to an external device other than an MDM service.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-008900 - Apple iOS/iPadOS must implement the management setting: remove managed applications upon unenrollment from MDM.
AIOS-13-010500 - Apple iOS/iPadOS must require a valid password be successfully entered before the mobile device data is unencrypted.

ACCESS CONTROL

AIOS-13-010600 - Apple iOS/iPadOS must implement the management setting: limit Ad Tracking.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-010700 - Apple iOS/iPadOS must implement the management setting: not allow automatic completion of Safari browser passcodes.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-010800 - Apple iOS/iPadOS must implement the management setting: Encrypt iTunes backups / Encrypt local backup.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-010900 - Apple iOS/iPadOS must implement the management setting: not allow use of Handoff.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-011100 - Apple iOS/iPadOS must implement the management setting: require the user to enter a password when connecting to an AirPlay.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-011200 - Apple iOS/iPadOS must implement the management setting: Disable Allow MailDrop.
AIOS-13-011300 - Apple iOS/iPadOS must implement the management setting: Disable Allow Shared Albums.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-011400 - iPhone and iPad must have the latest available iOS operating system installed.
AIOS-13-011500 - Apple iOS/iPadOS must implement the management setting: use SSL for Exchange ActiveSync.
AIOS-13-011600 - Apple iOS/iPadOS must implement management setting: not allow messages in an ActiveSync Exchange account to be forwarded.
AIOS-13-011700 - Apple iOS/iPadOS must implement the management setting: Treat Airdrop as an unmanaged destination.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-011800 - Apple iOS/iPadOS must implement the management setting: not have any Family Members in Family Sharing.
AIOS-13-011900 - Apple iOS/iPadOS must implement the management setting: not share location data through iCloud.
AIOS-13-012100 - Apple iOS/iPadOS must implement the management setting: force Apple Watch wrist detection.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-012200 - Apple iOS/iPadOS users must complete required training.
AIOS-13-012300 - A managed photo app must be used to take and store work-related photos.
AIOS-13-012500 - Apple iOS/iPadOS must implement the management setting: enable USB Restricted Mode.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-012600 - Apple iOS/iPadOS must not allow managed apps to write contacts to unmanaged contacts accounts.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-012700 - Apple iOS/iPadOS must not allow unmanaged apps to read contacts from managed contacts accounts.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-013000 - Apple iOS/iPadOS must implement the management setting: disable AirDrop.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-013100 - Apple iOS/iPadOS must implement the management setting: disable paired Apple Watch.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-013200 - Apple iOS/iPadOS must disable password autofill in browsers and applications.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-013300 - Apple iOS/iPadOS must disable allow setting up new nearby devices.
AIOS-13-013400 - Apple iOS/iPadOS must disable password proximity requests.
AIOS-13-013500 - Apple iOS/iPadOS must disable password sharing.

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-13-013600 - Apple iOS/iPadOS must disable Find My Friends in the Find My app.
AIOS-13-013700 - The Apple iOS/iPadOS must be Supervised by the MDM.