3.2.1.30 Ensure 'Allow password sharing (supervised only)' is set to 'Disabled'

Information

This recommendation pertains to sharing credentials between devices, such as through AirDrop.

Rationale:

Allowing password sharing may increase the likelihood of an institutionally related credential being moved to a non-institutionally controlled device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Allow password sharing (supervised only).

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/6168

Item Details

Category: ACCESS CONTROL, AWARENESS AND TRAINING, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-17, 800-53|AC-17(1), 800-53|AT-2, 800-53|SC-7, 800-53|SI-4, CSCv7|12.12, CSCv7|17.5

Plugin: MDM

Control ID: 4a3dda92d7660a46e42cdf5cbd44ad60bc02f7ff34e71e65858475bb99ff1c2f