AIOS-01-080006 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.

Information

Passwords provide a form of access control that prevents unauthorized individuals from accessing computing resources and sensitive data. Passwords may also be a source of entropy for generation of key encryption or data encryption keys. If a password is not required to access data, this data is accessible to any adversary who obtains physical possession of the device. Requiring that a password be successfully entered before the mobile device data is unencrypted mitigates this risk.

Note: MDF PP v2.0 requires a Password Authentication Factor and requires management of its length and complexity. It leaves open whether the existence of a password is subject to management. This STIGID addresses the configuration to require a password, which is critical to the cybersecurity posture of the device.

Solution

Install a configuration profile to require a password to unlock the device.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_iOS_10_V1R3_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CAT|I, CCI|CCI-002476, Rule-ID|SV-86403r1_rule, STIG-ID|AIOS-01-080006, Vuln-ID|V-71779

Plugin: MDM

Control ID: aa6b6237ac2b74f166d0e209f58fd9d0f2e63576481b0e5d13787a91371b8e6d