AIOS-16-013200 - The Apple iOS/iPadOS 16 must be supervised by the MDM.

Information

When an iOS/iPadOS is not supervised, the DoD mobile service provider cannot control when new iOS/iPadOS updates are installed on site-managed devices. Most updates should be installed immediately to mitigate new security vulnerabilities, while some sites need to test each update prior to installation to ensure critical missions are not adversely impacted by the update.

Several password and data protection controls can be implemented only when an Apple device is supervised.

SFR ID: FMT_SMF_EXT.1.1 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Use one of the following methods to supervise iOS and iPadOS devices managed by the DoD mobile service provider.

Method 1:
- Register all current and new iOS and iPadOS devices in the DoD mobile service provider's Automated Device Management/Apple Business Manager (ABM) account.
- Enable supervision of managed iOS/iPadOS devices in the MDM.

Method 2:
- Configure each iOS/iPadOS device using the Apple Configurator tool for Supervision.
- This method is usually only appropriate when MDM management of the DoD Apple device is not appropriate or an older device cannot be registered in ABM.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_iOS-iPadOS_16_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-20(2), 800-53|CM-6(1), 800-53|CM-6b., CAT|II, CCI|CCI-000097, CCI|CCI-000366, CCI|CCI-000370, Rule-ID|SV-254633r959010_rule, STIG-ID|AIOS-16-013200, Vuln-ID|V-254633

Plugin: MDM

Control ID: 252b0e6ed1e0f06668f3af6172ebbe7e0d61dabd78a349a05ec4d4f1936d26b6