STIGQter STIGQter: STIG Summary: Apple iOS/iPadOS 18 Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 13 May 2026:

The Apple iOS/iPadOS 18 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DOD servers; - Allows synchronization of data or applications between devices associated with user; - Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers; - Backs up its own data to a remote system; and - Uses artificial intelligence (AI), which processes data in the cloud (off device). Exception: Apple Intelligence Private Cloud Compute (PCC).

DISA Rule

SV-267997r1042532_rule

Vulnerability Number

V-267997

Group Title

PP-MDF-333070

Rule Version

AIOS-18-007400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install a configuration profile with an allow list of approved apps (allowlistedAppBundleIDs). Ensure the allow list does not include apps with the following characteristics:

- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers;
- Backs up its own data to a remote system; and
- Uses AI, which processes data in the cloud (off device). Exception: Apple Intelligence Private Cloud Compute (PCC).

Check Contents

Verify no apps with the following prohibited characteristics are included in the configuration profile:

- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers;
- Backs up its own data to a remote system; and
- Uses AI, which processes data in the cloud (off device). Exception: Apple Intelligence Private Cloud Compute (PCC).

This check procedure is performed on the Apple iOS/iPadOS management tool.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple iOS/iPadOS management tool, verify "Allow Listed App" (allowlistedAppBundleIDs) is configured and there are no apps with prohibited characteristics.

If "Allow listed apps" is not configured and contains apps with prohibited characteristics, this is a finding.

Vulnerability Number

V-267997

Documentable

False

Rule Version

AIOS-18-007400

Severity Override Guidance

Verify no apps with the following prohibited characteristics are included in the configuration profile:

- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers;
- Backs up its own data to a remote system; and
- Uses AI, which processes data in the cloud (off device). Exception: Apple Intelligence Private Cloud Compute (PCC).

This check procedure is performed on the Apple iOS/iPadOS management tool.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple iOS/iPadOS management tool, verify "Allow Listed App" (allowlistedAppBundleIDs) is configured and there are no apps with prohibited characteristics.

If "Allow listed apps" is not configured and contains apps with prohibited characteristics, this is a finding.

Check Content Reference

M

Target Key

5650