Check: AIOS-01-080006
Apple iOS 8 ISCG:
AIOS-01-080006
(in version v1 r1)
Title
Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted. (Cat I impact)
Discussion
Encryption is only effective if the decryption procedure is protected. If an adversary can easily access the private key (either directly or through a software application), sensitive DoD data is likely to be disclosed. Password protection is one method to reduce the likelihood of such an occurrence. SFR ID: FMT_SMF.1.1 #42
Check Content
Review configuration settings to confirm the device is set to require a passcode before use. This procedure is performed on the iOS device. On the iOS device: 1. Lock the device. 2. Wait the duration of the “Grace Lock” period. 3. Attempt to unlock the device. 4. Verify the unlock screen cannot be bypassed without entering a passcode. If the unlock screen can be bypassed without entering a passcode, this is a finding.
Fix Text
Install a Configuration Profile to require a password to unlock the device.
Additional Identifiers
Rule ID:
Vulnerability ID: V-54241
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |