4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devices

Information

This recommendation pertains to remote device locating, locking, and erasure by the end user.

Rationale:

The ability to locate, lock, and erase a device remotely helps mitigate the impact of device theft and loss, as well as the likelihood of permanent loss.

This is only recommended for end user-owned devices. Institutionally-owned devices should not be erasable by end users.

Impact:

Evidence may be destroyed if an end user performs an erase.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the device:

Tap Settings.

Tap <_The User's Name_> where Apple ID, iCloud, iTunes & App Store is displayed beneath.

Tap Find My.

Enable Find My iPhone, Find My Network and Send Last Location.

See Also

https://workbench.cisecurity.org/benchmarks/15548

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-7, 800-53|SC-4, CSCv7|14.5

Plugin: MDM

Control ID: 913bf354adf6d2031b4d9ee767a0f5b3e19a0e29c9385ec0179123299ed168a2