Check: AIOS-12-012300
Apple iOS 12 STIG:
AIOS-12-012300
(in versions v2 r1 through v1 r1)
Title
A managed photo app must be used to take and store work related photos. (Cat II impact)
Discussion
The iOS Photos app is unmanaged and may sync photo's with a device user's personal iCloud account. Therefore work related photos should not be taken via the iOS camera app or stored in the Photos app. A managed photo app should be used to take and manage work related photos. SFR ID: NA
Check Content
Review configuration settings to confirm a managed photos app is installed on the iOS device. This check procedure is performed on the Apple iOS device. On the Apple iOS device: 1. Open the Settings app. 2. Tap "General". 3. Tap "Profiles & Device Management". 4. Tap the DoD Configuration Profile from the Apple iOS management tool. 5. Tap "Apps". 6. Verify a photo capture and management app is listed. If a managed photo capture and management app is not installed on the iOS device, this is a finding.
Fix Text
Install a managed photos app to take and manage work related photos.
Additional Identifiers
Rule ID: SV-96553r1_rule
Vulnerability ID: V-81839
Group Title: PP-MDF-991000
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000097 |
The organization restricts or prohibits the use of organization-controlled portable storage devices by authorized individuals on external information systems. |
Controls
Number | Title |
---|---|
AC-20 (2) |
Portable Storage Devices |