4.1.6 Ensure 'Stolen Device Protection' Is Enabled

Information

With the release of iOS and iPadOS 17.3, Apple added the ability to restrict when a passcode can be reset. Turning this on will protect a user if their phone is stolen and the thief has obtained the user's passcode. If the passcode is compromised, a user's iCloud credentials can be reset or altered, giving access to the user's AppleID.

To access your significant locations follow this guide: Delete significant locations on iPhone.

To learn more about what access to an AppleID allows: Where can I use my Apple ID?

Rationale:

Requiring a user to be in a significant location to reset the passcode can hinder (or thwart) the takeover of a user's identity, through iCloud, in the case of a stolen device.

Impact:

This could cause an issue for the user if they are trying to change their passcode outside of their significant location(s).

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the device:

Tap Settings

Tap Face ID & Passcode

Enter the passcode

Tap Stolen Device Protection

Enable Stolen Device Protection

See Also

https://workbench.cisecurity.org/benchmarks/15548

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: MDM

Control ID: 32c596fdf1739d0045f0726b5b657ad4d6187150bee28bdb94a1e74d63de1f5d