4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devices

Information

This recommendation pertains to remote device locating, locking, and erasure by the end user.

Rationale:

The ability to locate, lock, and erase a device remotely helps mitigate the impact of device theft and loss, as well as the likelihood of permanent loss.

This is only recommended for end user-owned devices. Institutionally-owned devices should not be erasable by end users.

Impact:

Evidence may be destroyed if an end user performs an erase.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the device:

Tap Settings.

Tap <_The User's Name_> where Apple ID, iCloud, iTunes & App Store is displayed beneath.

Tap Find My.

Enable Find My iPhone, Find My Network and Send Last Location.

See Also

https://workbench.cisecurity.org/benchmarks/17713

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-7, 800-53|SC-4, CSCv7|14.5

Plugin: MDM

Control ID: 81df505ba4c07dc6d1436706ec72ce627841b76944b1c45463539c4273e0b4a4