Check: AIOS-18-018000
Apple iOS/iPadOS 18 STIG:
AIOS-18-018000
(in version v1 r4)
Title
DOD Apple iOS/iPadOS 18 devices must disable screenshots and screen recordings. (Cat II impact)
Discussion
A screenshot or screen recording of sensitive DOD information could lead to the inadvertent exposure of that information.
Check Content
Review configuration settings to confirm screenshot and screen recording is disabled. This check procedure is performed on both the device management tool and the iPhone and iPad device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the iOS/iPadOS management tool, verify "Allow screenshot and screen recording" is unchecked. On the iPhone/iPad device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the iOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Screen capture not allowed" is listed. If "Allow screenshot and screen recording" is listed in the management tool or "Screen capture not allowed" is not listed on the Apple device, this is a finding.
Fix Text
Install a configuration profile to disable the screenshot and screen recording.
Additional Identifiers
Rule ID: SV-276198r1115631_rule
Vulnerability ID: V-276198
Group Title: PP-MDF-993300
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |