3.2.1.32 Ensure 'Show Notification Center in Lock screen' is set to 'Disabled'

Information

This recommendation pertains to the display of Notification Center on the lock screen.

Rationale:

Communications between the operating system and applications to a user should be controlled to prevent data leakage or exploitation. For example, some two-factor authentication applications will present the option to allow a login from a new device in notification center on the lock screen.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Show Notification Center in Lock screen.

Deploy the Configuration Profile.

Additional Information:

The per-application notification settings described later in the benchmark can be used in lieu of disabling Notification Center at the lock screen. This should only be done if there is confidence that all applications producing sensitive notifications can be managed.

See Also

https://workbench.cisecurity.org/benchmarks/15548