Check: AVOS-02-018000
Apple visionOS 2 STIG:
AVOS-02-018000
(in version v1 r1)
Title
DOD Apple visionOS 2 devices must disable screenshots and screen recordings. (Cat III impact)
Discussion
A screenshot or screen recording of sensitive DOD information could lead to the inadvertent exposure of that information. SFR ID: FMT_MOF_EXT.1.2 #47
Check Content
Review configuration settings to confirm screenshot and screen recording is disabled. This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify "Allow screenshot and screen recording" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Vision Pro management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Screen capture not allowed" is listed. If "Allow screenshot and screen recording" is listed in the management tool or "Screen capture not allowed" is not listed on the Apple device, this is a finding.
Fix Text
Install a configuration profile to disable the screenshot and screen recording.
Additional Identifiers
Rule ID: SV-276422r1148317_rule
Vulnerability ID: V-276422
Group Title: PP-MDF-993300
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-000366 |
Implement the security configuration settings. |
Controls
| Number | Title |
|---|---|
| CM-6 |
Configuration Settings |