2.2.1.5 Ensure 'Allow personalized ads delivered by Apple' is set to 'Disabled'

Information

Apple provides a framework that allows advertisers to target Apple users with advertisements relevant to them and their interests by means of a unique identifier. For such personalized advertisements to be delivered, however, detailed information is collected, correlated, and made available to advertisers. This information is valuable to both advertisers and attackers and has been used with other metadata to reveal users' identities.

Rationale:

Disabling the use of a unique identifier helps hinder the tracking of users, which in turn supports protection of user data.

Impact:

Users will see generic advertising rather than targeted advertising. Apple warns that this will reduce the number of relevant ads.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Allow personalized ads delivered by Apple.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548