AIOS-13-008900 - Apple iOS/iPadOS must implement the management setting: remove managed applications upon unenrollment from MDM.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

When a device is unenrolled from MDM, it is possible to relax the security policies that the MDM had implemented on the device. This may cause apps and data to be more vulnerable than prior to enrollment. Removing managed apps (and consequently the data maintained within) upon unenrollment mitigates this risk because on appropriately configured iPhone and iPads, DoD-sensitive information exists only within managed apps.

Satisfies: PP-MDF-302510, PP-MDF-302505, PP-MDF-301500, MDF-PP-2500, MDF-PP-301510

SFR ID: FMT_SMF_EXT.2.1, FMT_SMF_EXT.1.1 #47h

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a configuration profile to delete all managed apps upon device unenrollment.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_iOS_iPadOS_13_V1R1_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, CCI|CCI-000370, CCI|CCI-001199, Rule-ID|SV-106565r1_rule, STIG-ID|AIOS-13-008900, Vuln-ID|V-97461

Plugin: MDM

Control ID: 516970a771e7b513e3a423354d3b6e05f70610d65f12dfbad9b44771703c836b