3.2.1.4 Ensure 'Allow iCloud backup' is set to 'Disabled'

Information

This recommendation pertains to allowing iCloud backup.

This recommendation does block educational institutions from being able to use iCloud backup with devices issued to students. Because of this, we do not recommend educational institutions enable this recommendation for those devices.

Rationale:

iCloud backups are encrypted in transit and at rest within Apple's infrastructure, but there is no protection against restoring a backup to an unmanaged device. This potentially allows for data leakage.

Use of back-ups is strongly advised as they allow to create a copy of data that can be recovered in the event of failures, such as hardware or software failure, data corruption, or a human-caused event, or accidental deletion of data. Back-up copies allow data to be restored from an earlier point in time to help recovering from an unexpected event.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Allow iCloud backup.

Deploy the Configuration Profile.

Additional Information:

This recommendation is exclusively for institutionally-owned devices. If an institution is relying on Bring Your Own Device (BYOD), those devices should not contain sensitive material necessary to protect at this level.

See Also

https://workbench.cisecurity.org/benchmarks/15548