3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'

Information

This recommendation pertains to preventing proximity-based password sharing from institutionally-owned devices.

Rationale:

In an organizational context, access to systems and applications should be provisioned by role, with credentials only being transferred through supported credential management systems. Additionally, credential sharing requests may be exploited through a social engineering scheme.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Allow proximity based password sharing requests.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-17, 800-53|AC-17(1), 800-53|SC-7, 800-53|SI-4, CSCv7|12.12

Plugin: MDM

Control ID: c974b52b24f262de4a723e2f190e4f0666515df7e0b8eb0a761108f8f23dc199