3.2.1.10 Ensure 'Force encrypted backups' is set to 'Enabled'

Information

This recommendation pertains to iTunes backup encryption of iOS and iPadOS devices.

Rationale:

Data that are stored securely on an iOS or iPadOS device may be trivially accessed from a local computer. Forcing the encryption of backups significantly reduces the likelihood of sensitive data being compromised if the local host computer is compromised.

Impact:

End users must configure a password for the encrypted backup, the complexity of which is not managed.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, check the checkbox for Force encrypted backups.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548

Item Details

Category: CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CP-9, 800-53|SC-28, CSCv7|10.4

Plugin: MDM

Control ID: fdc81be86406a77d693bfcc8a01d819779b102075be703ed2d3efc21b9f512ff