2.18.1 Ensure On-Device Dictation Is Enabled

Information

In macOS 14.0 Sonoma, Apple released the ability to limit dictation to staying on-device and not sending data to the Siri servers. The use of dictation is likely to include editing documents with confidential information. While Apple does have controls to obfuscate voice data that exists on their servers, it is recommended that Dictation-collected information does not leave the local Mac.

Sending data from dictation to the Siri servers could allow data spillage to occur. From a control perspective, it is much safer to ensure information of various levels of confidentiality is retained locally.

Solution

Profile Method:

Create or edit a configuration profile with the following information:

- The PayloadType string is com.apple.applicationaccess
- The key to include is forceOnDeviceOnlyDictation
- The key must be set to <true/>

Impact:

Keeping all dictation on-device does not allow the system to better understand and learn, through machine learning, from the user.

See Also

https://workbench.cisecurity.org/benchmarks/15550

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: e3a9e60eff2090a643b946b181d113bae278e2cf3d75fc60ebf1d84b0dae59a4